CVE-2009-0192
Novell eDirectory <8.8 SP3 - RCE
Title source: llmDescription
Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based buffer overflow.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Praveen Darshanam · perldoswindows
https://www.exploit-db.com/exploits/8129
References (8)
Scores
EPSS
0.1631
EPSS Percentile
94.9%
Details
CWE
CWE-189
Status
published
Products (1)
novell/edirectory
8.8 sp3 (2 CPE variants)
Published
Jul 14, 2009
Tracked Since
Feb 18, 2026