CVE-2008-0927 is a denial-of-service vulnerability affecting dhost.exe in Novell eDirectory versions 8.7.3 prior to SP10 and 8.8.2. Attackers can exploit this by sending crafted HTTP requests containing multiple or comma-separated Connection headers, leading to high CPU consumption. With a CVSS score of 5.0, it is easily exploitable remotely without authentication, causing a partial availability impact. While not actively exploited in the wild and lacking significant community discussion, public exploit code exists, indicating a potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:2000:*:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:2003:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.