← Vulnerability feed

Vulnerability record · CVE-2008-0927 · published 14 April 2008

CVE-2008-0927: Novell eDirectory dhost.exe HTTP Connection header CPU exhaustion DoS

Microsoft · Windows Nt

dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 mishandles HTTP Connection headers, allowing a remote attacker to exhaust CPU by sending a request with multiple Connection headers or a Connection header containing multiple comma-separated values. The flaw is a resource-consumption denial of service against the directory service, and the record notes it may be similar to CVE-2008-1777.

5.0 CVSS 2.0 Medium EPSS 70% · top 0.6% CWE-399 · CWE-399
5.0CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values. NOTE: this might be similar to CVE-2008-1777.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityUnauthenticated remote availability impact with public exploit code and high EPSS, but limited to denial of service and affecting an old, likely legacy product.

What it is

dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 mishandles HTTP Connection headers, allowing a remote attacker to exhaust CPU by sending a request with multiple Connection headers or a Connection header containing multiple comma-separated values. The flaw is a resource-consumption denial of service against the directory service, and the record notes it may be similar to CVE-2008-1777.

Impact

An unauthenticated remote attacker can drive sustained CPU consumption on the eDirectory host, degrading or denying directory and authentication services to legitimate users. No confidentiality or integrity impact is described; the effect is availability loss.

Attack surface

Reachable over the network via HTTP requests to the eDirectory dhost.exe service, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high (0.7005, 99.3rd percentile) and an Exploit-DB entry (5547) exists, indicating public exploit code is available.

What to do

  • Upgrade Novell eDirectory 8.7.3 to SP10 or later, or 8.8.2 to a fixed build, per the Novell vendor advisory.
  • Restrict network access to the eDirectory HTTP/dhost service to trusted management networks only.
  • Rate-limit or filter HTTP requests containing repeated or multi-valued Connection headers at the perimeter or reverse proxy.
  • Monitor CPU usage on eDirectory hosts and alert on sustained spikes correlated with HTTP traffic.

Detection

  • Inspect HTTP request logs for multiple Connection headers or Connection headers with comma-separated values.
  • Alert on sustained CPU saturation on eDirectory/dhost.exe hosts.
  • Correlate spikes in inbound HTTP requests to the eDirectory service with host CPU metrics.
  • Watch for repeated requests from a single source targeting the eDirectory HTTP listener.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-0927 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2008-3008Windows Media Encoder ActiveX control stack buffer overflowThe WMEncProfileManager ActiveX control in wmex.dll, shipped with Microsoft Windows Media Encoder 9 Series, contains a stack-based buffer overflow. A…EPSS 55%analysed9.3CVE-2008-3012Microsoft digital image suite memory buffer overflow vulnerabilitygdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP…EPSS 31%9.3CVE-2008-3014Microsoft digital image suite memory buffer overflow vulnerabilityBuffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Ser…EPSS 37%9.3CVE-2007-5348Microsoft GDI+ gradient fill integer overflow leads to remote code executionGDI+ in a wide range of Microsoft products mishandles crafted gradient sizes in gradient fill input, causing an integer overflow that leads to a heap…EPSS 53%analysed9.3CVE-2008-1435Microsoft windows-nt code injection vulnerabilityWindows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted s…EPSS 29%9.3CVE-2008-1086Microsoft internet explorer code injection vulnerabilityThe HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vist…EPSS 31%9.3CVE-2008-1087Windows GDI stack buffer overflow via crafted EMF imageA stack-based buffer overflow exists in the Graphics Device Interface (GDI) of multiple Microsoft Windows versions when processing an EMF image file …EPSS 57%analysed9.3CVE-2006-0005Microsoft windows-nt memory buffer overflow vulnerabilityBuffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the d…EPSS 39%

Source: NIST National Vulnerability Database (record CVE-2008-0927), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.