dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values.  NOTE: this might be similar to CVE-2008-1777.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.851
                        
                    
                    
                        
                            EPSS Ranking 99.3%