{"api_version":"1","generated_at":"2026-07-23T04:33:06+00:00","cve":"CVE-2008-3159","urls":{"html":"https://cve.report/CVE-2008-3159","api":"https://cve.report/api/cve/CVE-2008-3159.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3159","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3159"},"summary":{"title":"CVE-2008-3159","description":"Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ftf2 allows remote attackers to execute arbitrary code via unspecified vectors that trigger a stack-based buffer overflow, related to \"flawed arithmetic.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2008-07-14 18:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-189","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://securitytracker.com/id?1020431","name":"http://securitytracker.com/id?1020431","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Novell eDirectory Integer Overflow in 'ds.dlm' Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30938","name":"http://secunia.com/advisories/30938","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Novell eDirectory ds.dlm Module Buffer Overflow - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/1999","name":"http://www.vupen.com/english/advisories/2008/1999","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-08-041/","name":"http://www.zerodayinitiative.com/advisories/ZDI-08-041/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/support/search.do?cmd=displayKC&sliceId=SAL_Public&externalId=3694858","name":"http://www.novell.com/support/search.do?cmd=displayKC&sliceId=SAL_Public&externalId=3694858","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Vulnerability: Integer overflow stack corruption","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/30085","name":"http://www.securityfocus.com/bid/30085","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Novell eDirectory 'ds.dlm' Module Integer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43589","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43589","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3159","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3159","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3159","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"edirectory","cpe6":"8.7.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3159","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"edirectory","cpe6":"8.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:28:41.602Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1020431","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1020431"},{"name":"30085","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30085"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.novell.com/support/search.do?cmd=displayKC&sliceId=SAL_Public&externalId=3694858"},{"name":"novell-edirectory-dsdlm-bo(43589)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43589"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-08-041/"},{"name":"ADV-2008-1999","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/1999"},{"name":"30938","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30938"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-07-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ftf2 allows remote attackers to execute arbitrary code via unspecified vectors that trigger a stack-based buffer overflow, related to \"flawed arithmetic.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1020431","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1020431"},{"name":"30085","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30085"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.novell.com/support/search.do?cmd=displayKC&sliceId=SAL_Public&externalId=3694858"},{"name":"novell-edirectory-dsdlm-bo(43589)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43589"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-08-041/"},{"name":"ADV-2008-1999","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/1999"},{"name":"30938","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30938"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3159","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ftf2 allows remote attackers to execute arbitrary code via unspecified vectors that trigger a stack-based buffer overflow, related to \"flawed arithmetic.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1020431","refsource":"SECTRACK","url":"http://securitytracker.com/id?1020431"},{"name":"30085","refsource":"BID","url":"http://www.securityfocus.com/bid/30085"},{"name":"http://www.novell.com/support/search.do?cmd=displayKC&sliceId=SAL_Public&externalId=3694858","refsource":"CONFIRM","url":"http://www.novell.com/support/search.do?cmd=displayKC&sliceId=SAL_Public&externalId=3694858"},{"name":"novell-edirectory-dsdlm-bo(43589)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43589"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-08-041/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-08-041/"},{"name":"ADV-2008-1999","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/1999"},{"name":"30938","refsource":"SECUNIA","url":"http://secunia.com/advisories/30938"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3159","datePublished":"2008-07-14T18:00:00.000Z","dateReserved":"2008-07-14T00:00:00.000Z","dateUpdated":"2024-08-07T09:28:41.602Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-07-14 18:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-189","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:novell:edirectory:8.7.3:*:*:*:*:*:*:*","matchCriteriaId":"029ADE6D-6761-4196-847C-A0EFB3A06341"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:edirectory:8.8:*:*:*:*:*:*:*","matchCriteriaId":"D7548D05-AD2B-46C3-9036-366585FFCB48"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3159","Ordinal":"1","Title":"CVE-2008-3159","CVE":"CVE-2008-3159","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3159","Ordinal":"1","NoteData":"Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ftf2 allows remote attackers to execute arbitrary code via unspecified vectors that trigger a stack-based buffer overflow, related to \"flawed arithmetic.\"","Type":"Description","Title":"CVE-2008-3159"},{"CveYear":"2008","CveId":"3159","Ordinal":"2","NoteData":"2008-07-14","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3159","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}