novell CVE Vulnerabilities & Metrics

Focus on novell vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About novell Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with novell. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total novell CVEs: 169
Earliest CVE date: 16 Sep 1993, 04:00 UTC
Latest CVE date: 04 Feb 2020, 20:15 UTC

Latest CVE reference: CVE-2020-8118

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical novell CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.42

Max CVSS: 10.0

Critical CVEs (≥9): 149

CVSS Range vs. Count

Range Count
0.0-3.9 38
4.0-6.9 338
7.0-8.9 126
9.0-10.0 149

CVSS Distribution Chart

Top 5 Highest CVSS novell CVEs

These are the five CVEs with the highest CVSS scores for novell, sorted by severity first and recency.

All CVEs for novell

CVE-2020-8118 novell vulnerability CVSS: 4.0 04 Feb 2020, 20:15 UTC

An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.

CVE-2015-6815 novell vulnerability CVSS: 2.7 31 Jan 2020, 22:15 UTC

The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.

CVE-2012-6345 novell vulnerability CVSS: 5.0 25 Jan 2020, 19:15 UTC

Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.

CVE-2012-6344 novell vulnerability CVSS: 4.3 25 Jan 2020, 19:15 UTC

Novell ZENworks Configuration Management before 11.2.4 allows XSS.

CVE-2013-4357 novell vulnerability CVSS: 5.0 31 Dec 2019, 19:15 UTC

The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.

CVE-2013-2016 novell vulnerability CVSS: 6.9 30 Dec 2019, 22:15 UTC

A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host.

CVE-2019-13730 novell vulnerability CVSS: 6.8 10 Dec 2019, 22:15 UTC

Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2019-9811 novell vulnerability CVSS: 5.1 23 Jul 2019, 14:15 UTC

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVE-2019-11717 novell vulnerability CVSS: 5.0 23 Jul 2019, 14:15 UTC

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVE-2019-11338 novell vulnerability CVSS: 6.8 19 Apr 2019, 00:29 UTC

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

CVE-2017-9277 novell vulnerability CVSS: 5.0 02 Mar 2018, 20:29 UTC

The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.

CVE-2017-9267 novell vulnerability CVSS: 5.0 02 Mar 2018, 20:29 UTC

In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.

CVE-2017-14496 novell vulnerability CVSS: 7.8 03 Oct 2017, 01:29 UTC

Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

CVE-2017-14494 novell vulnerability CVSS: 4.3 03 Oct 2017, 01:29 UTC

dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.

CVE-2017-13704 novell vulnerability CVSS: 5.0 03 Oct 2017, 01:29 UTC

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.

CVE-2016-5759 novell vulnerability CVSS: 6.9 08 Sep 2017, 18:29 UTC

The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.

CVE-2015-0786 novell vulnerability CVSS: 10.0 09 Aug 2017, 18:29 UTC

Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2015-0785 novell vulnerability CVSS: 5.0 09 Aug 2017, 18:29 UTC

com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders via the dirname variable.

CVE-2015-0784 novell vulnerability CVSS: 5.0 09 Aug 2017, 18:29 UTC

Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLogins for the maintenance variable.

CVE-2015-0783 novell vulnerability CVSS: 4.0 09 Aug 2017, 18:29 UTC

The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename variable.

CVE-2015-0782 novell vulnerability CVSS: 7.5 09 Aug 2017, 18:29 UTC

SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2015-0781 novell vulnerability CVSS: 7.5 09 Aug 2017, 18:29 UTC

Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors.

CVE-2015-0780 novell vulnerability CVSS: 7.5 09 Aug 2017, 18:29 UTC

SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2015-5219 novell vulnerability CVSS: 5.0 21 Jul 2017, 14:29 UTC

The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.

CVE-2017-8932 novell vulnerability CVSS: 4.3 06 Jul 2017, 16:29 UTC

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

CVE-2017-1000366 novell vulnerability CVSS: 7.2 19 Jun 2017, 16:29 UTC

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.

CVE-2016-9961 novell vulnerability CVSS: 10.0 06 Jun 2017, 18:29 UTC

game-music-emu before 0.6.1 mishandles unspecified integer values.

CVE-2016-9960 novell vulnerability CVSS: 2.1 06 Jun 2017, 18:29 UTC

game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).

CVE-2017-7995 novell vulnerability CVSS: 1.7 03 May 2017, 19:59 UTC

Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.

CVE-2017-7432 novell vulnerability CVSS: 7.5 03 May 2017, 05:59 UTC

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.

CVE-2017-7431 novell vulnerability CVSS: 6.8 03 May 2017, 05:59 UTC

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.

CVE-2017-7430 novell vulnerability CVSS: 4.3 03 May 2017, 05:59 UTC

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.

CVE-2017-5186 novell vulnerability CVSS: 4.3 27 Apr 2017, 14:59 UTC

Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.

CVE-2016-5762 novell vulnerability CVSS: 7.5 20 Apr 2017, 17:59 UTC

Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a heap-based buffer overflow.

CVE-2016-5761 novell vulnerability CVSS: 4.3 20 Apr 2017, 17:59 UTC

Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email.

CVE-2016-5760 novell vulnerability CVSS: 4.3 20 Apr 2017, 17:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/install/login.jsp or (2) PATH_INFO to gwadmin-console/index.jsp.

CVE-2016-9169 novell vulnerability CVSS: 4.3 23 Mar 2017, 06:59 UTC

A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScript in the context of a valid user's browser session by getting the user to click on a specially crafted link. This could lead to session compromise or other browser-based attacks.

CVE-2016-9168 novell vulnerability CVSS: 4.3 23 Mar 2017, 06:59 UTC

A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.

CVE-2016-9167 novell vulnerability CVSS: 5.0 23 Mar 2017, 06:59 UTC

NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL.

CVE-2016-5747 novell vulnerability CVSS: 5.0 23 Mar 2017, 06:59 UTC

A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies.

CVE-2014-9853 novell vulnerability CVSS: 4.3 17 Mar 2017, 14:59 UTC

Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.

CVE-2010-4314 novell vulnerability CVSS: 9.3 11 Mar 2017, 06:59 UTC

Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overflowing the "name" parameter.

CVE-2015-7976 novell vulnerability CVSS: 4.0 30 Jan 2017, 21:59 UTC

The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.

CVE-2017-5182 novell vulnerability CVSS: 7.8 23 Jan 2017, 15:59 UTC

Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that allows complete directory traversal and total information disclosure. This vulnerability is present on all versions of OES for linux, it applies to OES2015 SP1 before Maintenance Update 11080, OES2015 before Maintenance Update 11079, OES11 SP3 before Maintenance Update 11078, OES11 SP2 before Maintenance Update 11077).

CVE-2016-5763 novell vulnerability CVSS: 6.4 15 Nov 2016, 19:30 UTC

Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10990, OES11 SP3 before Scheduled Maintenance Update 10991, OES11 SP2 before Scheduled Maintenance Update 10989) might allow authenticated remote attackers to perform unauthorized file access and modification.

CVE-2016-1598 novell vulnerability CVSS: 3.5 27 Oct 2016, 20:59 UTC

XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.

CVE-2016-7796 novell vulnerability CVSS: 4.9 13 Oct 2016, 14:59 UTC

The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.

CVE-2016-7052 novell vulnerability CVSS: 5.0 26 Sep 2016, 19:59 UTC

crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.

CVE-2016-6306 novell vulnerability CVSS: 4.3 26 Sep 2016, 19:59 UTC

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.

CVE-2016-6304 novell vulnerability CVSS: 7.8 26 Sep 2016, 19:59 UTC

Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.

CVE-2016-4303 novell vulnerability CVSS: 7.5 26 Sep 2016, 14:59 UTC

The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.

CVE-2015-8924 novell vulnerability CVSS: 4.3 20 Sep 2016, 14:15 UTC

The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.

CVE-2015-8923 novell vulnerability CVSS: 4.3 20 Sep 2016, 14:15 UTC

The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.

CVE-2015-8922 novell vulnerability CVSS: 4.3 20 Sep 2016, 14:15 UTC

The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct.

CVE-2015-8921 novell vulnerability CVSS: 5.0 20 Sep 2016, 14:15 UTC

The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.

CVE-2015-8920 novell vulnerability CVSS: 4.3 20 Sep 2016, 14:15 UTC

The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.

CVE-2015-8919 novell vulnerability CVSS: 5.0 20 Sep 2016, 14:15 UTC

The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file.

CVE-2015-8918 novell vulnerability CVSS: 5.0 20 Sep 2016, 14:15 UTC

The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy."

CVE-2016-1611 novell vulnerability CVSS: 7.2 01 Aug 2016, 02:59 UTC

Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.sh, which allows local users to gain privileges by replacing this file's content with arbitrary shell commands.

CVE-2016-1610 novell vulnerability CVSS: 5.0 01 Aug 2016, 02:59 UTC

Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote attackers to bypass intended access restrictions and write to arbitrary files via a .. (dot dot) in a blob name.

CVE-2016-1609 novell vulnerability CVSS: 3.5 01 Aug 2016, 02:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input, as demonstrated by a crafted attribute of an IMG element in the phone field of a user profile.

CVE-2016-1608 novell vulnerability CVSS: 9.0 01 Aug 2016, 02:59 UTC

vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ntpServer parameter.

CVE-2016-1607 novell vulnerability CVSS: 6.5 01 Aug 2016, 02:59 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Security Update 2 allow remote attackers to hijack the authentication of administrators, as demonstrated by reconfiguring time settings via a vaconfig/time request.

CVE-2016-4957 novell vulnerability CVSS: 5.0 05 Jul 2016, 01:59 UTC

ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.

CVE-2016-4956 novell vulnerability CVSS: 5.0 05 Jul 2016, 01:59 UTC

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.

CVE-2016-4955 novell vulnerability CVSS: 4.3 05 Jul 2016, 01:59 UTC

ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.

CVE-2016-4997 novell vulnerability CVSS: 7.2 03 Jul 2016, 21:59 UTC

The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.

CVE-2016-1704 novell vulnerability CVSS: 6.8 03 Jul 2016, 21:59 UTC

Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVE-2016-5829 novell vulnerability CVSS: 7.2 27 Jun 2016, 10:59 UTC

Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call.

CVE-2016-5828 novell vulnerability CVSS: 7.2 27 Jun 2016, 10:59 UTC

The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.

CVE-2016-4470 novell vulnerability CVSS: 4.9 27 Jun 2016, 10:59 UTC

The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.

CVE-2016-3707 novell vulnerability CVSS: 6.8 27 Jun 2016, 10:59 UTC

The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a cookie, or an attack that occurs after reading the local icmp_echo_sysrq file.

CVE-2016-1583 novell vulnerability CVSS: 7.2 27 Jun 2016, 10:59 UTC

The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.

CVE-2014-9904 novell vulnerability CVSS: 7.2 27 Jun 2016, 10:59 UTC

The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.

CVE-2016-2834 novell vulnerability CVSS: 9.3 13 Jun 2016, 10:59 UTC

Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.

CVE-2016-2818 novell vulnerability CVSS: 6.8 13 Jun 2016, 10:59 UTC

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2016-2815 novell vulnerability CVSS: 6.8 13 Jun 2016, 10:59 UTC

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2016-0376 novell vulnerability CVSS: 5.1 03 Jun 2016, 14:59 UTC

The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.

CVE-2016-0363 novell vulnerability CVSS: 6.8 03 Jun 2016, 14:59 UTC

The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.

CVE-2016-4913 novell vulnerability CVSS: 7.2 23 May 2016, 10:59 UTC

The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.

CVE-2016-4805 novell vulnerability CVSS: 7.2 23 May 2016, 10:59 UTC

Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.

CVE-2016-4569 novell vulnerability CVSS: 2.1 23 May 2016, 10:59 UTC

The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.

CVE-2016-4486 novell vulnerability CVSS: 2.1 23 May 2016, 10:59 UTC

The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.

CVE-2016-4485 novell vulnerability CVSS: 5.0 23 May 2016, 10:59 UTC

The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.

CVE-2016-4482 novell vulnerability CVSS: 2.1 23 May 2016, 10:59 UTC

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.

CVE-2016-3951 novell vulnerability CVSS: 4.9 02 May 2016, 10:59 UTC

Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor.

CVE-2016-3689 novell vulnerability CVSS: 4.9 02 May 2016, 10:59 UTC

The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface.

CVE-2016-3140 novell vulnerability CVSS: 4.9 02 May 2016, 10:59 UTC

The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.

CVE-2016-3138 novell vulnerability CVSS: 4.9 02 May 2016, 10:59 UTC

The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data endpoint descriptor.

CVE-2016-3137 novell vulnerability CVSS: 4.9 02 May 2016, 10:59 UTC

drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoint descriptor, related to the cypress_generic_port_probe and cypress_open functions.

CVE-2016-3136 novell vulnerability CVSS: 4.9 02 May 2016, 10:59 UTC

The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device without two interrupt-in endpoint descriptors.

CVE-2016-2188 novell vulnerability CVSS: 4.9 02 May 2016, 10:59 UTC

The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.

CVE-2016-2187 novell vulnerability CVSS: 4.9 02 May 2016, 10:59 UTC

The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.

CVE-2016-2186 novell vulnerability CVSS: 4.9 02 May 2016, 10:59 UTC

The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.

CVE-2016-2185 novell vulnerability CVSS: 4.9 02 May 2016, 10:59 UTC

The ati_remote2_probe function in drivers/input/misc/ati_remote2.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.

CVE-2016-3672 novell vulnerability CVSS: 4.6 27 Apr 2016, 17:59 UTC

The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid program, by disabling stack-consumption resource limits.

CVE-2016-3156 novell vulnerability CVSS: 2.1 27 Apr 2016, 17:59 UTC

The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses.

CVE-2016-3139 novell vulnerability CVSS: 4.9 27 Apr 2016, 17:59 UTC

The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.

CVE-2016-3134 novell vulnerability CVSS: 7.2 27 Apr 2016, 17:59 UTC

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.

CVE-2016-2847 novell vulnerability CVSS: 4.9 27 Apr 2016, 17:59 UTC

fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes.

CVE-2016-2384 novell vulnerability CVSS: 4.9 27 Apr 2016, 17:59 UTC

Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an invalid USB descriptor.

CVE-2016-2184 novell vulnerability CVSS: 4.9 27 Apr 2016, 17:59 UTC

The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via a crafted endpoints value in a USB device descriptor.

CVE-2015-8845 novell vulnerability CVSS: 4.9 27 Apr 2016, 17:59 UTC

The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.

CVE-2015-8816 novell vulnerability CVSS: 7.2 27 Apr 2016, 17:59 UTC

The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.

CVE-2015-8812 novell vulnerability CVSS: 10.0 27 Apr 2016, 17:59 UTC

drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.

CVE-2015-1339 novell vulnerability CVSS: 4.9 27 Apr 2016, 17:59 UTC

Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.

CVE-2016-1596 novell vulnerability CVSS: 3.5 22 Apr 2016, 10:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4) ta_selectedTopicContent, (5) tf_orgUnitName, (6) tf_aManufacturerFullName, (7) tf_aManufacturerName, (8) tf_aManufacturerAddress, or (9) tf_aManufacturerCity parameter.

CVE-2016-1595 novell vulnerability CVSS: 4.0 22 Apr 2016, 10:59 UTC

LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.

CVE-2016-1594 novell vulnerability CVSS: 4.0 22 Apr 2016, 10:59 UTC

Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.

CVE-2016-1593 novell vulnerability CVSS: 6.5 22 Apr 2016, 10:59 UTC

Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.

CVE-2016-1658 novell vulnerability CVSS: 4.3 18 Apr 2016, 10:59 UTC

The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.

CVE-2016-1657 novell vulnerability CVSS: 4.3 18 Apr 2016, 10:59 UTC

The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.

CVE-2015-8550 novell vulnerability CVSS: 5.7 14 Apr 2016, 14:59 UTC

Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.

CVE-2015-8552 novell vulnerability CVSS: 1.7 13 Apr 2016, 15:59 UTC

The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and XEN_PCI_OP_enable_msi operations, aka "Linux pciback missing sanity checks."

CVE-2015-5968 novell vulnerability CVSS: 4.3 18 Mar 2016, 10:59 UTC

Cross-site scripting (XSS) vulnerability in Novell Filr 1.2 before Hot Patch 4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2016-1957 novell vulnerability CVSS: 4.3 13 Mar 2016, 18:59 UTC

Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.

CVE-2016-1956 novell vulnerability CVSS: 7.1 13 Mar 2016, 18:59 UTC

Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.

CVE-2016-1955 novell vulnerability CVSS: 4.3 13 Mar 2016, 18:59 UTC

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

CVE-2016-1954 novell vulnerability CVSS: 6.8 13 Mar 2016, 18:59 UTC

The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or possibly gain privileges by specifying a URL of a local file.

CVE-2016-1953 novell vulnerability CVSS: 6.8 13 Mar 2016, 18:59 UTC

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors.

CVE-2016-1952 novell vulnerability CVSS: 6.8 13 Mar 2016, 18:59 UTC

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2016-1629 novell vulnerability CVSS: 10.0 21 Feb 2016, 18:59 UTC

Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.

CVE-2015-5970 novell vulnerability CVSS: 5.0 18 Feb 2016, 22:59 UTC

The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.

CVE-2015-7566 novell vulnerability CVSS: 4.9 08 Feb 2016, 03:59 UTC

The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint.

CVE-2015-7833 novell vulnerability CVSS: 4.9 19 Oct 2015, 10:59 UTC

The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor.

CVE-2014-0611 novell vulnerability CVSS: 4.3 22 Jul 2015, 14:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014 before Support Pack 2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2015-2743 novell vulnerability CVSS: 7.5 06 Jul 2015, 02:01 UTC

PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workers, which might allow remote attackers to execute arbitrary code by leveraging a Same Origin Policy bypass.

CVE-2015-2740 novell vulnerability CVSS: 10.0 06 Jul 2015, 02:01 UTC

Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.

CVE-2015-2739 novell vulnerability CVSS: 10.0 06 Jul 2015, 02:01 UTC

The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.

CVE-2015-2736 novell vulnerability CVSS: 9.3 06 Jul 2015, 02:01 UTC

The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.

CVE-2015-2735 novell vulnerability CVSS: 9.3 06 Jul 2015, 02:01 UTC

nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.

CVE-2015-2733 novell vulnerability CVSS: 10.0 06 Jul 2015, 02:01 UTC

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a dedicated worker.

CVE-2015-2730 novell vulnerability CVSS: 4.3 06 Jul 2015, 02:01 UTC

Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which makes it easier for remote attackers to spoof ECDSA signatures via unspecified vectors.

CVE-2015-2728 novell vulnerability CVSS: 7.5 06 Jul 2015, 02:00 UTC

The IndexedDatabaseManager class in the IndexedDB implementation in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 misinterprets an unspecified IDBDatabase field as a pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors, related to a "type confusion" issue.

CVE-2015-2726 novell vulnerability CVSS: 10.0 06 Jul 2015, 02:00 UTC

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2015-2725 novell vulnerability CVSS: 10.0 06 Jul 2015, 02:00 UTC

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2015-2724 novell vulnerability CVSS: 10.0 06 Jul 2015, 02:00 UTC

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2015-2722 novell vulnerability CVSS: 10.0 06 Jul 2015, 02:00 UTC

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker.

CVE-2015-2721 novell vulnerability CVSS: 4.3 06 Jul 2015, 02:00 UTC

Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.

CVE-2015-0779 novell vulnerability CVSS: 10.0 07 Jun 2015, 23:59 UTC

Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a crafted directory name in the uid parameter, in conjunction with a WAR filename in the filename parameter and WAR content in the POST data, a different vulnerability than CVE-2010-5323 and CVE-2010-5324.

CVE-2010-5324 novell vulnerability CVSS: 10.0 07 Jun 2015, 23:59 UTC

Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code via a zenworks-fileupload request with a crafted directory name in the type parameter, in conjunction with a WAR filename in the filename parameter and WAR content in the POST data, a different vulnerability than CVE-2010-5323.

CVE-2010-5323 novell vulnerability CVSS: 10.0 07 Jun 2015, 23:59 UTC

Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code via a crafted WAR pathname in the filename parameter in conjunction with WAR content in the POST data, a different vulnerability than CVE-2010-5324.

CVE-2015-2716 novell vulnerability CVSS: 7.5 14 May 2015, 10:59 UTC

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

CVE-2015-2713 novell vulnerability CVSS: 6.8 14 May 2015, 10:59 UTC

Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading Style Sheets (CSS) token sequence containing properties related to vertical text.

CVE-2015-2710 novell vulnerability CVSS: 6.8 14 May 2015, 10:59 UTC

Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.

CVE-2015-2709 novell vulnerability CVSS: 7.5 14 May 2015, 10:59 UTC

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2015-2708 novell vulnerability CVSS: 7.5 14 May 2015, 10:59 UTC

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2015-2567 novell vulnerability CVSS: 3.5 16 Apr 2015, 17:00 UTC

Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Privileges.

CVE-2015-2566 novell vulnerability CVSS: 2.8 16 Apr 2015, 17:00 UTC

Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via vectors related to DML.

CVE-2015-0459 novell vulnerability CVSS: 10.0 16 Apr 2015, 16:59 UTC

Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JavaFX 2.2.76, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2015-0491.

CVE-2015-0458 novell vulnerability CVSS: 7.6 16 Apr 2015, 16:59 UTC

Unspecified vulnerability in in Oracle Java SE 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2015-0439 novell vulnerability CVSS: 4.0 16 Apr 2015, 16:59 UTC

Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-4756.

CVE-2015-0438 novell vulnerability CVSS: 4.0 16 Apr 2015, 16:59 UTC

Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition.

CVE-2015-0423 novell vulnerability CVSS: 4.0 16 Apr 2015, 16:59 UTC

Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

CVE-2015-0405 novell vulnerability CVSS: 4.0 16 Apr 2015, 16:59 UTC

Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to XA.

CVE-2015-3044 novell vulnerability CVSS: 5.0 14 Apr 2015, 22:59 UTC

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.

CVE-2015-3043 novell vulnerability CVSS: 10.0 14 Apr 2015, 22:59 UTC

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.

CVE-2015-0240 novell vulnerability CVSS: 10.0 24 Feb 2015, 01:59 UTC

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

CVE-2015-0437 novell vulnerability CVSS: 9.3 21 Jan 2015, 19:59 UTC

Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVE-2015-0421 novell vulnerability CVSS: 6.9 21 Jan 2015, 19:59 UTC

Unspecified vulnerability in Oracle Java SE 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the installation process.

CVE-2015-0412 novell vulnerability CVSS: 7.2 21 Jan 2015, 19:59 UTC

Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS.

CVE-2015-0410 novell vulnerability CVSS: 5.0 21 Jan 2015, 18:59 UTC

Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.

CVE-2015-0408 novell vulnerability CVSS: 10.0 21 Jan 2015, 18:59 UTC

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.

CVE-2015-0406 novell vulnerability CVSS: 5.8 21 Jan 2015, 18:59 UTC

Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality and availability via unknown vectors related to Deployment.

CVE-2015-0403 novell vulnerability CVSS: 6.9 21 Jan 2015, 18:59 UTC

Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2015-0400 novell vulnerability CVSS: 5.0 21 Jan 2015, 18:59 UTC

Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries.

CVE-2015-0395 novell vulnerability CVSS: 9.3 21 Jan 2015, 18:59 UTC

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVE-2015-0383 novell vulnerability CVSS: 5.4 21 Jan 2015, 18:59 UTC

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot.

CVE-2014-6601 novell vulnerability CVSS: 10.0 21 Jan 2015, 18:59 UTC

Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVE-2014-5213 novell vulnerability CVSS: 4.0 19 Dec 2014, 18:59 UTC

nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote authenticated users to obtain sensitive information from process memory via a direct request.

CVE-2014-5212 novell vulnerability CVSS: 4.3 19 Dec 2014, 18:59 UTC

Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote attackers to inject arbitrary web script or HTML via the rdn parameter.

CVE-2014-8559 novell vulnerability CVSS: 4.9 10 Nov 2014, 11:55 UTC

The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.

CVE-2014-3690 novell vulnerability CVSS: 4.9 10 Nov 2014, 11:55 UTC

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm access, as demonstrated by PR_SET_TSC prctl calls within a modified copy of QEMU.

CVE-2014-3687 novell vulnerability CVSS: 7.8 10 Nov 2014, 11:55 UTC

The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.

CVE-2014-3566 novell vulnerability CVSS: 4.3 15 Oct 2014, 00:55 UTC

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

CVE-2014-7970 novell vulnerability CVSS: 4.9 13 Oct 2014, 10:55 UTC

The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call.

CVE-2012-6657 novell vulnerability CVSS: 4.9 28 Sep 2014, 10:55 UTC

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.

CVE-2014-7169 novell vulnerability CVSS: 10.0 25 Sep 2014, 01:55 UTC

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

CVE-2014-6271 novell vulnerability CVSS: 10.0 24 Sep 2014, 18:48 UTC

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

CVE-2014-0610 novell vulnerability CVSS: 10.0 05 Sep 2014, 01:55 UTC

The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.

CVE-2014-0600 novell vulnerability CVSS: 7.8 29 Aug 2014, 09:55 UTC

FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.

CVE-2014-0609 novell vulnerability CVSS: 10.0 17 Aug 2014, 18:55 UTC

Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintenance Update 9413 for Linux has unknown impact and attack vectors.

CVE-2014-0599 novell vulnerability CVSS: 4.3 18 Jun 2014, 17:55 UTC

Cross-site scripting (XSS) vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-0598 novell vulnerability CVSS: 10.0 18 Jun 2014, 17:55 UTC

Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified impact and remote attack vectors.

CVE-2014-0595 novell vulnerability CVSS: 2.6 08 May 2014, 10:55 UTC

/opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic circumstances by leveraging the granting of the F permission by an administrator.

CVE-2011-0993 novell vulnerability CVSS: 2.1 16 Apr 2014, 18:37 UTC

SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.

CVE-2014-0592 novell vulnerability CVSS: 7.5 04 Apr 2014, 14:55 UTC

Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass security group restrictions via unspecified vectors, related to floating IPs.

CVE-2014-1505 novell vulnerability CVSS: 5.0 19 Mar 2014, 10:55 UTC

The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing attack involving feDisplacementMap elements, a related issue to CVE-2013-1693.

CVE-2013-3706 novell vulnerability CVSS: 5.0 06 Mar 2014, 11:55 UTC

Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595.

CVE-2013-1096 novell vulnerability CVSS: 4.3 28 Dec 2013, 04:53 UTC

Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId.

CVE-2013-3709 novell vulnerability CVSS: 7.2 23 Dec 2013, 23:55 UTC

WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.

CVE-2013-3705 novell vulnerability CVSS: 4.9 22 Dec 2013, 15:16 UTC

The VBA32 AntiRootKit component for Novell Client 2 SP3 before IR5 on Windows allows local users to cause a denial of service (bugcheck and BSOD) via an IOCTL call for an invalid IOCTL.

CVE-2013-7042 novell vulnerability CVSS: 4.6 10 Dec 2013, 16:55 UTC

SUSE Lifecycle Management Server (SLMS) before 1.3.7 uses world-readable permissions for the secret keys, which allows local users to gain privileges via unspecified vectors.

CVE-2013-3710 novell vulnerability CVSS: 4.3 10 Dec 2013, 16:55 UTC

SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of this key from a product installation elsewhere.

CVE-2012-0434 novell vulnerability CVSS: 10.0 02 Dec 2013, 04:36 UTC

The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecified impact and attack vectors.

CVE-2012-0426 novell vulnerability CVSS: 7.2 02 Dec 2013, 04:36 UTC

Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an unspecified impact via vectors related to a tmp/ directory.

CVE-2012-0414 novell vulnerability CVSS: 4.3 02 Dec 2013, 04:36 UTC

Cross-site scripting (XSS) vulnerability in the Spacewalk service in SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11 SP1 allows remote attackers to inject arbitrary web script or HTML via an image name.

CVE-2013-3707 novell vulnerability CVSS: 4.3 01 Dec 2013, 17:55 UTC

The HTTPSTK service in the novell-nrm package before 2.0.2-297.305.302.3 in Novell Open Enterprise Server 2 (OES 2) Linux, and OES 11 Linux Gold and SP1, does not make the intended SSL_free and SSL_shutdown calls for the close of a TCP connection, which allows remote attackers to cause a denial of service (service crash) by establishing many TCP connections to port 8009.

CVE-2013-3708 novell vulnerability CVSS: 5.0 01 Dec 2013, 04:31 UTC

The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to cause a denial of service via unspecified vectors.

CVE-2013-4589 novell vulnerability CVSS: 4.3 23 Nov 2013, 11:55 UTC

The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.

CVE-2013-4419 novell vulnerability CVSS: 6.8 05 Nov 2013, 20:55 UTC

The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.

CVE-2013-6347 novell vulnerability CVSS: 6.8 02 Nov 2013, 20:55 UTC

Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors.

CVE-2013-6346 novell vulnerability CVSS: 6.8 02 Nov 2013, 20:55 UTC

Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2013-6345 novell vulnerability CVSS: 10.0 02 Nov 2013, 20:55 UTC

Unspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors related to an "Application Exception."

CVE-2013-6344 novell vulnerability CVSS: 4.3 02 Nov 2013, 20:55 UTC

The ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows attackers to conduct cross-frame scripting attacks via unknown vectors.

CVE-2013-1084 novell vulnerability CVSS: 5.0 02 Nov 2013, 19:55 UTC

Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename parameter in a GetFile action to zenworks-unmaninv/.

CVE-2013-3704 novell vulnerability CVSS: 4.3 28 Oct 2013, 22:55 UTC

The RPM GPG key import and handling feature in libzypp 12.15.0 and earlier reports a different key fingerprint than the one used to sign a repository when multiple key blobs are used, which might allow remote attackers to trick users into believing that the repository was signed by a more-trustworthy key.

CVE-2013-3567 novell vulnerability CVSS: 7.5 19 Aug 2013, 23:55 UTC

Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.

CVE-2013-3956 novell vulnerability CVSS: 7.2 31 Jul 2013, 13:20 UTC

The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows Server 2008; and Novell Client 2 SP3 on Windows Server 2008 R2, Windows 7, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted 0x143B6B IOCTL call.

CVE-2013-3697 novell vulnerability CVSS: 7.2 31 Jul 2013, 13:20 UTC

Integer overflow in the NWFS.SYS kernel driver 4.91.5.8 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003 and the NCPL.SYS kernel driver in Novell Client 2 SP2 on Windows Vista and Windows Server 2008 and Novell Client 2 SP3 on Windows Server 2008 R2, Windows 7, Windows 8, and Windows Server 2012 might allow local users to gain privileges via a crafted 0x1439EB IOCTL call.

CVE-2013-4854 novell vulnerability CVSS: 7.8 29 Jul 2013, 13:59 UTC

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.

CVE-2013-1087 novell vulnerability CVSS: 4.3 15 Jul 2013, 20:55 UTC

Cross-site scripting (XSS) vulnerability in the client in Novell GroupWise through 8.0.3 HP3, and 2012 through SP2, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML via the body of an e-mail message.

CVE-2013-1097 novell vulnerability CVSS: 4.3 17 Jun 2013, 11:38 UTC

Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onload event.

CVE-2013-1095 novell vulnerability CVSS: 4.3 17 Jun 2013, 11:38 UTC

Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError event.

CVE-2013-1094 novell vulnerability CVSS: 4.3 17 Jun 2013, 11:38 UTC

Cross-site scripting (XSS) vulnerability in a ZCC page in zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via an invalid locale.

CVE-2013-1093 novell vulnerability CVSS: 5.8 17 Jun 2013, 11:38 UTC

Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the directToPage parameter.

CVE-2013-1092 novell vulnerability CVSS: 7.2 05 May 2013, 11:07 UTC

Multiple unquoted Windows search path vulnerabilities in Novell ZENworks Desktop Management (ZDM) 7 through 7.1 might allow local users to gain privileges via a Trojan horse "program" file in the C: folder, related to an attempted launch of (1) ZenRem32.exe or (2) wm.exe.

CVE-2013-1091 novell vulnerability CVSS: 10.0 02 May 2013, 18:55 UTC

Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2013-3268 novell vulnerability CVSS: 10.0 24 Apr 2013, 10:28 UTC

Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.

CVE-2013-1088 novell vulnerability CVSS: 6.8 24 Apr 2013, 10:28 UTC

Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.

CVE-2013-1086 novell vulnerability CVSS: 4.3 19 Apr 2013, 11:44 UTC

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError attribute.

CVE-2013-1379 novell vulnerability CVSS: 10.0 10 Apr 2013, 03:48 UTC

Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 do not properly initialize pointer arrays, which allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVE-2013-2770 novell vulnerability CVSS: 5.8 07 Apr 2013, 17:55 UTC

The installation functionality in the Novell Kanaka component before 2.8 for Novell Open Enterprise Server (OES) on Mac OS X does not verify the server's X.509 certificate during an SSL session, which allows man-in-the-middle attackers to spoof servers via an arbitrary certificate.

CVE-2013-1085 novell vulnerability CVSS: 9.3 29 Mar 2013, 16:09 UTC

Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earlier, and Novell Messenger 2.1.x and 2.2.x before 2.2.2, allows remote attackers to execute arbitrary code via an import command containing a long string in the filename parameter.

CVE-2013-1083 novell vulnerability CVSS: 10.0 29 Mar 2013, 16:09 UTC

Unspecified vulnerability in the login functionality in the Reporting Module in Novell Identity Manager (aka IDM) Roles Based Provisioning Module 4.0.2 before Field Patch C has unknown impact and attack vectors.

CVE-2013-1082 novell vulnerability CVSS: 7.5 29 Mar 2013, 16:09 UTC

Directory traversal vulnerability in DUSAP.php in Novell ZENworks Mobile Management before 2.7.1 allows remote attackers to include and execute arbitrary local files via the language parameter.

CVE-2013-1080 novell vulnerability CVSS: 10.0 29 Mar 2013, 16:09 UTC

The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently upload and execute arbitrary programs, via a request to TCP port 443.

CVE-2013-1079 novell vulnerability CVSS: 6.8 29 Mar 2013, 16:09 UTC

Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers to execute arbitrary local DLL files via a crafted web page that also calls the Initialize method.

CVE-2012-6534 novell vulnerability CVSS: 4.3 29 Mar 2013, 16:08 UTC

Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results "Save Query As" "Save As Retention Policy" action.

CVE-2013-1081 novell vulnerability CVSS: 7.5 11 Mar 2013, 21:55 UTC

Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote attackers to include and execute arbitrary local files via the language parameter.

CVE-2013-0804 novell vulnerability CVSS: 10.0 24 Feb 2013, 04:37 UTC

The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via unspecified vectors.

CVE-2012-0439 novell vulnerability CVSS: 9.3 24 Feb 2013, 04:37 UTC

An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method.

CVE-2012-0411 novell vulnerability CVSS: 10.0 24 Dec 2012, 18:55 UTC

Unspecified vulnerability in Novell iPrint Client before 5.82 allows remote attackers to execute arbitrary code via an op-client-interface-version action.

CVE-2012-4959 novell vulnerability CVSS: 10.0 18 Nov 2012, 19:55 UTC

Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.

CVE-2012-4958 novell vulnerability CVSS: 7.8 18 Nov 2012, 19:55 UTC

Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.

CVE-2012-4957 novell vulnerability CVSS: 7.8 18 Nov 2012, 19:55 UTC

Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record.

CVE-2012-4956 novell vulnerability CVSS: 10.0 18 Nov 2012, 19:55 UTC

Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record.

CVE-2012-4933 novell vulnerability CVSS: 7.8 20 Oct 2012, 18:55 UTC

The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of Scott for the (1) GetFile_Password and (2) GetConfigInfo_Password operations, which allows remote attackers to obtain sensitive information via a crafted rtrlet/rtr request for the HandleMaintenanceCalls function.

CVE-2012-4912 novell vulnerability CVSS: 4.3 28 Sep 2012, 10:40 UTC

Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to inject arbitrary web script or HTML via a crafted signature in an HTML e-mail message.

CVE-2012-0419 novell vulnerability CVSS: 5.0 28 Sep 2012, 10:40 UTC

Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrary files via directory traversal sequences in a request.

CVE-2012-0418 novell vulnerability CVSS: 9.3 28 Sep 2012, 10:40 UTC

Unspecified vulnerability in the client in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted file.

CVE-2012-0417 novell vulnerability CVSS: 10.0 28 Sep 2012, 10:40 UTC

Integer overflow in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2012-0272 novell vulnerability CVSS: 4.3 19 Sep 2012, 10:57 UTC

Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to inject arbitrary web script or HTML via the merge parameter.

CVE-2012-0271 novell vulnerability CVSS: 10.0 19 Sep 2012, 10:57 UTC

Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow, as demonstrated by a request with -1 in the Content-Length HTTP header.

CVE-2011-3827 novell vulnerability CVSS: 4.3 19 Sep 2012, 10:57 UTC

The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted date-time string in a .ics attachment.

CVE-2012-0421 novell vulnerability CVSS: 2.1 08 Aug 2012, 10:26 UTC

The SUSE Audit Log Keeper daemon before 0.2.1-0.4.6.1 for SUSE Manager and Spacewalk uses world-readable permissions for /etc/auditlog-keeper.conf, which allows local users to obtain passwords by reading this file.

CVE-2011-3174 novell vulnerability CVSS: 6.8 26 Jul 2012, 22:55 UTC

Buffer overflow in the DoFindReplace function in the ISGrid.Grid2.1 ActiveX control in InstallShield/ISGrid2.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary code via a long bstrReplaceText parameter.

CVE-2011-2658 novell vulnerability CVSS: 6.8 26 Jul 2012, 22:55 UTC

The ISList.ISAvi ActiveX control in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 provides access to the mscomct2.ocx file, which allows remote attackers to execute arbitrary code by leveraging unspecified mscomct2 flaws.

CVE-2011-2657 novell vulnerability CVSS: 6.8 26 Jul 2012, 22:55 UTC

Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary commands via a pathname in the first argument.

CVE-2012-0410 novell vulnerability CVSS: 5.0 05 Jul 2012, 14:55 UTC

Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attackers to read arbitrary files via the User.interface parameter.

CVE-2011-4914 novell vulnerability CVSS: 6.4 21 Jun 2012, 23:55 UTC

The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket.

CVE-2011-4913 novell vulnerability CVSS: 7.8 21 Jun 2012, 23:55 UTC

The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.

CVE-2012-2313 novell vulnerability CVSS: 1.2 13 Jun 2012, 10:24 UTC

The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.

CVE-2012-2223 novell vulnerability CVSS: 4.3 11 Apr 2012, 10:39 UTC

The xplat agent in Novell ZENworks Configuration Management (ZCM) 10.3.x before 10.3.4 and 11.x before 11.2 enables the HTTP TRACE method, which might make it easier for remote attackers to conduct cross-site tracing (XST) attacks via unspecified vectors.

CVE-2012-2215 novell vulnerability CVSS: 5.0 09 Apr 2012, 21:55 UTC

Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to read arbitrary files via an opcode 0x21 request.

CVE-2011-4188 novell vulnerability CVSS: 4.0 09 Apr 2012, 20:55 UTC

Buffer overflow in the Create Attribute function in jclient in Novell iManager 2.7.4 before patch 4 allows remote authenticated users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted EnteredAttrName parameter, a related issue to CVE-2010-1929.

CVE-2011-3176 novell vulnerability CVSS: 10.0 09 Apr 2012, 20:55 UTC

Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x4c request.

CVE-2011-3175 novell vulnerability CVSS: 10.0 09 Apr 2012, 20:55 UTC

Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x6c request.

CVE-2011-4189 novell vulnerability CVSS: 7.5 02 Mar 2012, 22:55 UTC

The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via a long e-mail address in an Address Book (aka .NAB) file.

CVE-2011-4187 novell vulnerability CVSS: 10.0 21 Feb 2012, 13:31 UTC

Buffer overflow in the GetDriverSettings function in nipplib.dll in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code via a long realm field, a different vulnerability than CVE-2011-3173.

CVE-2011-4186 novell vulnerability CVSS: 9.3 21 Feb 2012, 13:31 UTC

Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code via a crafted client-file-name parameter in a printer-url, a different vulnerability than CVE-2011-1705.

CVE-2011-4185 novell vulnerability CVSS: 10.0 21 Feb 2012, 13:31 UTC

The GetPrinterURLList2 method in the ActiveX control in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2008-2431 and CVE-2008-2436.

CVE-2011-4194 novell vulnerability CVSS: 7.5 02 Feb 2012, 04:09 UTC

Buffer overflow in Novell iPrint Server in Novell Open Enterprise Server 2 (OES2) through SP3 on Linux allows remote attackers to execute arbitrary code via a crafted attributes-natural-language field.

CVE-2011-1710 novell vulnerability CVSS: 7.5 31 Dec 2011, 01:55 UTC

Multiple integer overflows in the HTTP server in the Novell XTier framework 3.1.8 allow remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via crafted header length variables.

CVE-2011-5028 novell vulnerability CVSS: 4.0 29 Dec 2011, 22:55 UTC

Directory traversal vulnerability in novelllogmanager/FileDownload in Novell Sentinel Log Manager 1.2.0.1_938 and earlier, as used in Novell Sentinel before 7.0.1.0, allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.

CVE-2011-3179 novell vulnerability CVSS: 5.0 08 Dec 2011, 11:55 UTC

The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.04 and earlier, allows remote attackers to read from arbitrary memory locations via a crafted command.

CVE-2011-2653 novell vulnerability CVSS: 10.0 08 Dec 2011, 11:55 UTC

Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote attackers to execute arbitrary code by uploading an executable file.

CVE-2011-4191 novell vulnerability CVSS: 7.5 30 Nov 2011, 04:05 UTC

Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (abend or NFS outage) via long packets.

CVE-2011-3173 novell vulnerability CVSS: 7.5 30 Nov 2011, 04:05 UTC

Stack-based buffer overflow in the GetDriverSettings function in nipplib.dll in the iPrint client in Novell Open Enterprise Server 2 (aka OES2) SP3 allows remote attackers to execute arbitrary code via a long (1) hostname or (2) port field.

CVE-2011-2656 novell vulnerability CVSS: 9.3 24 Oct 2011, 17:55 UTC

Unspecified vulnerability in ZfHSrvr.exe in Novell ZENworks Handheld Management (ZHM) 7 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2655.

CVE-2011-2655 novell vulnerability CVSS: 9.3 24 Oct 2011, 17:55 UTC

Unspecified vulnerability in ZfHSrvr.exe in Novell ZENworks Handheld Management (ZHM) 7 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2656.

CVE-2011-2663 novell vulnerability CVSS: 10.0 08 Oct 2011, 02:52 UTC

Array index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted yearly RRULE variable in a VCALENDAR attachment in an e-mail message.

CVE-2011-2662 novell vulnerability CVSS: 10.0 08 Oct 2011, 02:52 UTC

Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a negative BYWEEKNO property in a weekly RRULE variable in a VCALENDAR attachment in an e-mail message.

CVE-2011-2661 novell vulnerability CVSS: 4.3 08 Oct 2011, 02:52 UTC

Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Directory.Item.name or (2) Directory.Item.displayName parameter.

CVE-2011-2227 novell vulnerability CVSS: 4.3 08 Oct 2011, 02:52 UTC

Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 709603.

CVE-2011-2219 novell vulnerability CVSS: 5.0 08 Oct 2011, 02:52 UTC

Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2218.

CVE-2011-2218 novell vulnerability CVSS: 5.0 08 Oct 2011, 02:52 UTC

Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2219.

CVE-2011-1696 novell vulnerability CVSS: 4.3 08 Oct 2011, 02:52 UTC

Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 692972.

CVE-2011-0334 novell vulnerability CVSS: 10.0 08 Oct 2011, 02:52 UTC

Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file.

CVE-2011-0333 novell vulnerability CVSS: 10.0 08 Oct 2011, 02:52 UTC

Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted TZNAME variable in a VCALENDAR attachment in an e-mail message, related to an "integer truncation error."

CVE-2011-2654 novell vulnerability CVSS: 9.3 06 Sep 2011, 15:55 UTC

The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect privileges associated with a partially initialized session.

CVE-2011-2652 novell vulnerability CVSS: 4.3 23 Aug 2011, 21:55 UTC

Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted archive file list that is used in an overlay file.

CVE-2011-2651 novell vulnerability CVSS: 7.5 23 Aug 2011, 21:55 UTC

Unspecified vulnerability in the file browser in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename.

CVE-2011-2650 novell vulnerability CVSS: 4.3 23 Aug 2011, 21:55 UTC

Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RPM info display.

CVE-2011-2649 novell vulnerability CVSS: 7.5 23 Aug 2011, 21:55 UTC

Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.

CVE-2011-2648 novell vulnerability CVSS: 7.5 23 Aug 2011, 21:55 UTC

Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a filter in a modified file.

CVE-2011-2647 novell vulnerability CVSS: 7.5 23 Aug 2011, 21:55 UTC

Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted archive name in the list of testdrive modified files.

CVE-2011-2646 novell vulnerability CVSS: 7.5 23 Aug 2011, 21:55 UTC

Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename in the list of testdrive modified files.

CVE-2011-2645 novell vulnerability CVSS: 7.5 23 Aug 2011, 21:55 UTC

Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename for a custom RPM.

CVE-2011-2644 novell vulnerability CVSS: 4.3 23 Aug 2011, 21:55 UTC

Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display.

CVE-2011-2226 novell vulnerability CVSS: 4.3 23 Aug 2011, 21:55 UTC

Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listing.

CVE-2011-2225 novell vulnerability CVSS: 9.3 23 Aug 2011, 21:55 UTC

Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to have an unknown impact via a crafted directory pathname that is inserted into config.sh.

CVE-2011-3014 novell vulnerability CVSS: 5.0 09 Aug 2011, 22:55 UTC

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not properly restrict caching of HTTPS responses, which makes it easier for remote attackers to obtain sensitive information by leveraging an unattended workstation.

CVE-2011-3013 novell vulnerability CVSS: 5.0 09 Aug 2011, 22:55 UTC

WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVE-2011-2224 novell vulnerability CVSS: 4.3 09 Aug 2011, 22:55 UTC

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVE-2011-2223 novell vulnerability CVSS: 5.0 09 Aug 2011, 22:55 UTC

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

CVE-2011-2222 novell vulnerability CVSS: 4.3 09 Aug 2011, 22:55 UTC

Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors.

CVE-2011-2221 novell vulnerability CVSS: 5.0 09 Aug 2011, 22:55 UTC

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and obtain sensitive GroupWise information via unspecified vectors.

CVE-2011-2750 novell vulnerability CVSS: 5.0 17 Jul 2011, 20:55 UTC

NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.

CVE-2011-2220 novell vulnerability CVSS: 10.0 14 Jul 2011, 23:55 UTC

Stack-based buffer overflow in NFREngine.exe in Novell File Reporter Engine before 1.0.2.53, as used in Novell File Reporter and other products, allows remote attackers to execute arbitrary code via a crafted RECORD element.

CVE-2011-1708 novell vulnerability CVSS: 9.3 09 Jun 2011, 21:55 UTC

Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs cookie.

CVE-2011-1707 novell vulnerability CVSS: 9.3 09 Jun 2011, 19:55 UTC

Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs parameter in a printer-url.

CVE-2011-1706 novell vulnerability CVSS: 9.3 09 Jun 2011, 19:55 UTC

Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted iprint-client-config-info parameter in a printer-url.

CVE-2011-1705 novell vulnerability CVSS: 9.3 09 Jun 2011, 19:55 UTC

Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted client-file-name parameter in a printer-url.

CVE-2011-1704 novell vulnerability CVSS: 9.3 09 Jun 2011, 19:55 UTC

Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted core-package parameter in a printer-url.

CVE-2011-1703 novell vulnerability CVSS: 9.3 09 Jun 2011, 19:55 UTC

Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted driver-version parameter in a printer-url.

CVE-2011-1702 novell vulnerability CVSS: 9.3 09 Jun 2011, 19:55 UTC

Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted file-date-time parameter in a printer-url.

CVE-2011-1701 novell vulnerability CVSS: 9.3 09 Jun 2011, 19:55 UTC

Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted profile-name parameter in a printer-url.

CVE-2011-1700 novell vulnerability CVSS: 9.3 09 Jun 2011, 19:55 UTC

Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted profile-time parameter in a printer-url.

CVE-2011-1699 novell vulnerability CVSS: 9.3 09 Jun 2011, 19:55 UTC

Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted uri parameter in a printer-url.

CVE-2011-1711 novell vulnerability CVSS: 5.5 09 Jun 2011, 02:38 UTC

Unspecified vulnerability in the Mobility Pack 1.1.2 and earlier in Novell Data Synchronizer 1.0.x, and 1.1.x through 1.1.1 build 428, allows remote authenticated users to access the accounts of other users via unknown vectors.

CVE-2011-0995 novell vulnerability CVSS: 2.1 13 May 2011, 17:05 UTC

The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.

CVE-2010-4229 novell vulnerability CVSS: 10.0 18 Apr 2011, 18:55 UTC

Directory traversal vulnerability in an unspecified servlet in the Inventory component in ZENworks Asset Management (ZAM) in Novell ZENworks Configuration Management 10.3 before 10.3.2, and 11, allows remote attackers to overwrite files, and subsequently execute arbitrary code, via directory traversal sequences in a filename field in an upload request.

CVE-2011-0988 novell vulnerability CVSS: 4.4 18 Apr 2011, 17:55 UTC

pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors.

CVE-2011-0992 novell vulnerability CVSS: 5.8 13 Apr 2011, 21:55 UTC

Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain sensitive information via vectors related to member data in a resurrected MonoThread instance.

CVE-2011-0991 novell vulnerability CVSS: 6.8 13 Apr 2011, 21:55 UTC

Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to finalizing and then resurrecting a DynamicMethod instance.

CVE-2011-0990 novell vulnerability CVSS: 5.8 13 Apr 2011, 21:55 UTC

Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to trigger a buffer overflow and modify internal data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file in which a thread makes a change after a type check but before a copy action.

CVE-2011-0989 novell vulnerability CVSS: 5.8 13 Apr 2011, 21:55 UTC

The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which allows remote attackers to modify internal read-only data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file, as demonstrated by modifying a C# struct.

CVE-2011-0466 novell vulnerability CVSS: 6.4 10 Apr 2011, 02:51 UTC

The API in SUSE openSUSE Build Service (OBS) 2.0.x before 2.0.8 and 2.1.x before 2.1.6 allows attackers to bypass intended write-access restrictions and modify a (1) package or (2) project via unspecified vectors.

CVE-2011-0462 novell vulnerability CVSS: 4.3 10 Apr 2011, 02:51 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the login page in the webui component in SUSE openSUSE Build Service (OBS) before 2.1.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2011-1551 novell vulnerability CVSS: 6.9 30 Mar 2011, 22:55 UTC

SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gain privileges by leveraging access to this account during root filesystem operations by the Cobbler daemon.

CVE-2010-4228 novell vulnerability CVSS: 9.0 22 Mar 2011, 17:55 UTC

Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary code or cause a denial of service (abend) via a long DELE command, a different vulnerability than CVE-2010-0625.4.

CVE-2011-0464 novell vulnerability CVSS: 10.0 09 Mar 2011, 23:00 UTC

Unspecified vulnerability in Novell Vibe OnPrem 3.0 before Hot Patch 1 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2010-4227 novell vulnerability CVSS: 10.0 25 Feb 2011, 19:00 UTC

The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port UDP 1234, leading to a stack-based buffer overflow.

CVE-2010-4328 novell vulnerability CVSS: 7.5 19 Feb 2011, 01:00 UTC

Multiple stack-based buffer overflows in opt/novell/iprint/bin/ipsmd in Novell iPrint for Linux Open Enterprise Server 2 SP2 and SP3 allow remote attackers to execute arbitrary code via unspecified LPR opcodes.

CVE-2010-4323 novell vulnerability CVSS: 7.5 19 Feb 2011, 01:00 UTC

Heap-based buffer overflow in novell-tftp.exe in Novell ZENworks Configuration Manager (ZCM) 10.3.1, 10.3.2, and 11.0, and earlier versions, allows remote attackers to execute arbitrary code via a long TFTP request.

CVE-2010-4327 novell vulnerability CVSS: 5.0 10 Feb 2011, 18:00 UTC

Unspecified vulnerability in the NCP service in Novell eDirectory 8.8.5 before 8.8.5.6 and 8.8.6 before 8.8.6.2 allows remote attackers to cause a denial of service (hang) via a malformed FileSetLock request to port 524.

CVE-2011-0742 novell vulnerability CVSS: 10.0 02 Feb 2011, 01:00 UTC

Buffer overflow in ZfHIPCND.exe in Novell ZENworks Handheld Management 7.0 allows remote attackers to execute arbitrary code via a crafted IP Conduit packet to TCP port 2400.

CVE-2010-4717 novell vulnerability CVSS: 6.5 31 Jan 2011, 20:00 UTC

Multiple stack-based buffer overflows in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a long (1) LIST or (2) LSUB command.

CVE-2010-4716 novell vulnerability CVSS: 4.3 31 Jan 2011, 20:00 UTC

Cross-site scripting (XSS) vulnerability in the WebPublisher component in Novell GroupWise before 8.02HP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-4715 novell vulnerability CVSS: 5.0 31 Jan 2011, 20:00 UTC

Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agent components in Novell GroupWise before 8.02HP allow remote attackers to read arbitrary files via unspecified vectors. NOTE: some of these details are obtained from third party information.

CVE-2010-4714 novell vulnerability CVSS: 10.0 31 Jan 2011, 20:00 UTC

Multiple stack-based buffer overflows in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) gwpoa.exe in the Post Office Agent, (2) gwmta.exe in the Message Transfer Agent, (3) gwia.exe in the Internet Agent, (4) the WebAccess Agent, or (5) the Monitor Agent.

CVE-2010-4713 novell vulnerability CVSS: 10.0 31 Jan 2011, 20:00 UTC

Integer signedness error in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a signed integer value in the Content-Type header.

CVE-2010-4712 novell vulnerability CVSS: 10.0 31 Jan 2011, 20:00 UTC

Multiple stack-based buffer overflows in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a Content-Type header containing (1) multiple items separated by ; (semicolon) characters or (2) crafted string data.

CVE-2010-4711 novell vulnerability CVSS: 10.0 31 Jan 2011, 20:00 UTC

Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a large parameter in a LIST command.

CVE-2010-2779 novell vulnerability CVSS: 4.3 28 Jan 2011, 22:00 UTC

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to "replies."

CVE-2010-2778 novell vulnerability CVSS: 4.3 28 Jan 2011, 22:00 UTC

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to a "Javascript XSS exploit."

CVE-2010-2777 novell vulnerability CVSS: 9.0 28 Jan 2011, 22:00 UTC

Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to execute arbitrary code via a long mailbox name in a CREATE command.

CVE-2010-4326 novell vulnerability CVSS: 10.0 28 Jan 2011, 21:00 UTC

Multiple buffer overflows in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via variables in a VCALENDAR message, as demonstrated by a long (1) REQUEST-STATUS, (2) TZNAME, (3) COMMENT, or (4) RRULE variable in this message.

CVE-2010-4325 novell vulnerability CVSS: 10.0 28 Jan 2011, 21:00 UTC

Buffer overflow in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP2 allows remote attackers to execute arbitrary code via a crafted TZID variable in a VCALENDAR message.

CVE-2010-3912 novell vulnerability CVSS: 10.0 13 Jan 2011, 01:00 UTC

The supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not "disguise passwords" in configuration files, which has unknown impact and attack vectors.

CVE-2010-4322 novell vulnerability CVSS: 3.5 07 Jan 2011, 23:00 UTC

Cross-site scripting (XSS) vulnerability in gwtTeaming.rpc in Novell Vibe OnPrem 3 BETA allows remote authenticated users to inject arbitrary web script or HTML via the Micro Blog (aka What Are You Working On?) field.

CVE-2010-4324 novell vulnerability CVSS: 4.3 07 Jan 2011, 19:00 UTC

Cross-site scripting (XSS) vulnerability in the Approval Form in the User Application in the Roles Based Provisioning Module 3.7.0 before 370D in Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-4321 novell vulnerability CVSS: 9.3 30 Dec 2010, 19:00 UTC

Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote attackers to execute arbitrary code via a long argument to (1) the GetDriverSettings2 method, as reachable by (2) the GetDriverSettings method.

CVE-2010-4254 novell vulnerability CVSS: 7.5 06 Dec 2010, 13:44 UTC

Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.

CVE-2010-4299 novell vulnerability CVSS: 9.3 22 Nov 2010, 12:54 UTC

Heap-based buffer overflow in ZfHIPCND.exe in Novell Zenworks 7 Handheld Management (ZHM) allows remote attackers to execute arbitrary code via a crafted request to TCP port 2400.

CVE-2010-3110 novell vulnerability CVSS: 7.2 12 Oct 2010, 20:00 UTC

Multiple buffer overflows in the Novell Client novfs module for the Linux kernel in SUSE Linux Enterprise 11 SP1 and openSUSE 11.3 allow local users to gain privileges via unspecified vectors.

CVE-2010-3264 novell vulnerability CVSS: 2.1 08 Sep 2010, 20:00 UTC

The engine installer in Novell Identity Manager (aka IDM) 3.6.1 stores admin tree credentials in /tmp/idmInstall.log, which allows local users to obtain sensitive information by reading this file.

CVE-2010-1507 novell vulnerability CVSS: 5.0 03 Sep 2010, 20:00 UTC

WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.

CVE-2010-1325 novell vulnerability CVSS: 4.3 03 Sep 2010, 20:00 UTC

Cross-site request forgery (CSRF) vulnerability in the apache2-slms package in SUSE Lifecycle Management Server (SLMS) 1.0 on SUSE Linux Enterprise (SLE) 11 allows remote attackers to hijack the authentication of unspecified victims via vectors related to improper parameter quoting. NOTE: some sources report that this is a vulnerability in a product named "Apache SLMS," but that is incorrect.

CVE-2010-3109 novell vulnerability CVSS: 9.3 23 Aug 2010, 22:00 UTC

Stack-based buffer overflow in the browser plugin in Novell iPrint Client before 5.42 allows remote attackers to execute arbitrary code via a long operation parameter.

CVE-2010-3108 novell vulnerability CVSS: 9.3 23 Aug 2010, 22:00 UTC

Buffer overflow in the browser plugin in Novell iPrint Client before 5.42 allows remote attackers to execute arbitrary code by using EMBED elements to pass parameters with long names.

CVE-2010-3107 novell vulnerability CVSS: 7.1 23 Aug 2010, 22:00 UTC

A certain ActiveX control in ienipp.ocx in the browser plugin in Novell iPrint Client before 5.42 does not properly restrict the set of files to be deleted, which allows remote attackers to cause a denial of service (recursive file deletion) via unspecified vectors related to a "logic flaw" in the CleanUploadFiles method in the nipplib.dll module.

CVE-2010-3106 novell vulnerability CVSS: 9.3 23 Aug 2010, 22:00 UTC

The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the debug parameter, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a parameter value with a crafted length, related to the ExecuteRequest method.

CVE-2010-3105 novell vulnerability CVSS: 9.3 23 Aug 2010, 22:00 UTC

The PluginGetDriverFile function in Novell iPrint Client before 5.44 interprets an uninitialized memory location as a pointer value, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2010-1527 novell vulnerability CVSS: 9.3 23 Aug 2010, 22:00 UTC

Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter in an op-client-interface-version action.

CVE-2010-1930 novell vulnerability CVSS: 5.0 28 Jun 2010, 17:30 UTC

Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree parameter in a login request to nps/servlet/webacc.

CVE-2010-1929 novell vulnerability CVSS: 9.0 28 Jun 2010, 17:30 UTC

Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated users to execute arbitrary code via the (1) EnteredClassID or (2) NewClassName parameter to nps/servlet/webacc.

CVE-2010-2351 novell vulnerability CVSS: 10.0 21 Jun 2010, 19:30 UTC

Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitrary code via a Sessions Setup AndX packet with a long AccountName.

CVE-2010-0284 novell vulnerability CVSS: 10.0 18 Jun 2010, 16:30 UTC

Directory traversal vulnerability in the getEntry method in the PortalModuleInstallManager component in a servlet in nps.jar in the Administration Console (aka Access Management Console) in Novell Access Manager 3.1 before 3.1.2-281 on Windows allows remote attackers to create arbitrary files with any contents, and consequently execute arbitrary code, via a .. (dot dot) in a parameter, aka ZDI-CAN-678.

CVE-2009-4879 novell vulnerability CVSS: 4.3 26 May 2010, 18:30 UTC

The Identity Server in Novell Access Manager before 3.1 SP1 allows attackers with disabled Active Directory accounts to authenticate using X.509 authentication, which bypasses intended access restrictions.

CVE-2009-4878 novell vulnerability CVSS: 4.3 26 May 2010, 18:30 UTC

Unspecified vulnerability in the Administration Console in Novell Access Manager before 3.1 SP1 allows attackers to access system files via unknown attack vectors.

CVE-2010-0625 novell vulnerability CVSS: 6.5 05 Apr 2010, 16:30 UTC

Stack-based buffer overflow in NWFTPD.nlm before 5.10.01 in the FTP server in Novell NetWare 5.1 through 6.5 SP8 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long (1) MKD, (2) RMD, (3) RNFR, or (4) DELE command.

CVE-2007-6735 novell vulnerability CVSS: 7.5 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.08.06 in the FTP server in Novell NetWare does not properly handle partial matches for container names in the FTPREST.TXT file, which allows remote attackers to bypass intended access restrictions via an FTP session.

CVE-2007-6734 novell vulnerability CVSS: 4.0 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.08.07 in the FTP server in Novell NetWare 6.5 SP7 does not properly implement the FTPREST.TXT NOREMOTE restriction, which allows remote authenticated users to access directories outside of the home server via unspecified vectors.

CVE-2005-4888 novell vulnerability CVSS: 5.0 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.06.04 in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (excessive stale connections) by establishing many FTP sessions, which persist in the Not-Logged-In state after each session is completed.

CVE-2005-4887 novell vulnerability CVSS: 7.5 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.06.05 in the FTP server in Novell NetWare 6.5 SP5 allows attackers to have an unspecified impact via vectors related to passwords.

CVE-2004-2767 novell vulnerability CVSS: 4.3 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.04.25 in the FTP server in Novell NetWare does not promptly close DS sessions, which allows remote attackers to cause a denial of service (connection slot exhaustion) by establishing many FTP sessions that persist for the lifetime of a DS session.

CVE-2003-1596 novell vulnerability CVSS: 7.5 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.03.12 in the FTP server in Novell NetWare does not properly restrict filesystem use by anonymous users with NFS Gateway home directories, which allows remote attackers to bypass intended access restrictions via an FTP session.

CVE-2003-1595 novell vulnerability CVSS: 10.0 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly perform "intruder detection," which has unspecified impact and attack vectors.

CVE-2003-1594 novell vulnerability CVSS: 7.5 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly enforce FTPREST.TXT settings, which allows remote attackers to bypass intended access restrictions via an FTP session.

CVE-2003-1593 novell vulnerability CVSS: 7.5 05 Apr 2010, 15:30 UTC

NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 does not enforce domain-name login restrictions, which allows remote attackers to bypass intended access control via an FTP connection.

CVE-2003-1592 novell vulnerability CVSS: 5.0 05 Apr 2010, 15:30 UTC

Multiple buffer overflows in NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allow remote attackers to cause a denial of service (abend) via a long (1) username or (2) password.

CVE-2003-1591 novell vulnerability CVSS: 4.3 05 Apr 2010, 15:30 UTC

NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allows user-assisted remote attackers to cause a denial of service (console hang) via a large number of FTP sessions, which are not properly handled during an NLM unload.

CVE-2002-2434 novell vulnerability CVSS: 5.0 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.02i in the FTP server in Novell NetWare does not properly listen for data connections, which allows remote attackers to cause a denial of service (abend) via multiple FTP sessions.

CVE-2002-2433 novell vulnerability CVSS: 4.0 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote authenticated users to cause a denial of service (abend) via a crafted ABOR command.

CVE-2002-2432 novell vulnerability CVSS: 5.0 05 Apr 2010, 15:30 UTC

Unspecified vulnerability in NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via a crafted username.

CVE-2001-1587 novell vulnerability CVSS: 5.0 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.01w in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via an anonymous STOU command.

CVE-2000-1246 novell vulnerability CVSS: 3.5 05 Apr 2010, 15:30 UTC

NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allows remote authenticated users to cause a denial of service (abend) by sending an RNTO command after a failed RNFR command.

CVE-2000-1245 novell vulnerability CVSS: 7.5 05 Apr 2010, 15:30 UTC

Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors.

CVE-2009-4662 novell vulnerability CVSS: 4.3 03 Mar 2010, 20:30 UTC

Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 7.0 before 7.03 HP4 and 8.0 before 8.0 SP1 allows remote attackers to inject arbitrary web script or HTML via the User.Theme.index parameter.

CVE-2009-4655 novell vulnerability CVSS: 7.5 26 Feb 2010, 18:30 UTC

The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.

CVE-2009-4654 novell vulnerability CVSS: 9.0 26 Feb 2010, 18:30 UTC

Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code via long sadminpwd and verifypwd parameters in a submit action to /dhost/httpstk.

CVE-2009-4653 novell vulnerability CVSS: 9.0 26 Feb 2010, 18:30 UTC

Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a denial of service (dhost.exe crash) and possibly execute arbitrary code via a long string to /dhost/modules?I:.

CVE-2010-0666 novell vulnerability CVSS: 5.0 19 Feb 2010, 17:30 UTC

Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote attackers to cause a denial of service (crash) via unknown a crafted SOAP request, a different issue than CVE-2008-0926.

CVE-2010-0317 novell vulnerability CVSS: 7.8 15 Jan 2010, 18:30 UTC

Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP requests that are not properly handled by (1) the CIFS functionality in CIFS.nlm Semantic Agent (Build 163 MP) 3.27 or (2) the AFP functionality in AFPTCP.nlm Build 163 SP 3.27. NOTE: some of these details are obtained from third party information.

CVE-2009-4486 novell vulnerability CVSS: 7.5 08 Jan 2010, 18:30 UTC

Stack-based buffer overflow in the eDirectory plugin in Novell iManager before 2.7.3 allows remote attackers to execute arbitrary code via vectors that trigger long arguments to an unspecified sub-application, related to importing and exporting from a schema.

CVE-2009-1569 novell vulnerability CVSS: 9.3 08 Dec 2009, 23:30 UTC

Multiple stack-based buffer overflows in Novell iPrint Client 4.38, 5.30, and possibly other versions before 5.32 allow remote attackers to execute arbitrary code via vectors related to (1) Date and (2) Time.

CVE-2009-1568 novell vulnerability CVSS: 9.3 08 Dec 2009, 23:30 UTC

Stack-based buffer overflow in ienipp.ocx in Novell iPrint Client 5.30, and possibly other versions before 5.32, allows remote attackers to execute arbitrary code via a long target-frame parameter.

CVE-2009-0895 novell vulnerability CVSS: 10.0 03 Dec 2009, 17:30 UTC

Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containing a large integer value that triggers a heap-based buffer overflow.

CVE-2009-3863 novell vulnerability CVSS: 5.0 04 Nov 2009, 18:30 UTC

Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argument to the SetFontFace method.

CVE-2009-3862 novell vulnerability CVSS: 5.0 04 Nov 2009, 18:30 UTC

The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value.

CVE-2009-3547 novell vulnerability CVSS: 6.9 04 Nov 2009, 15:30 UTC

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.

CVE-2009-1297 novell vulnerability CVSS: 4.4 23 Oct 2009, 18:30 UTC

iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.

CVE-2009-2707 novell vulnerability CVSS: 4.9 18 Sep 2009, 10:30 UTC

Unspecified vulnerability in ia32el (aka the IA 32 emulation functionality) before 7042_7022-0.4.2 in SUSE Linux Enterprise (SLE) 10 SP2 on Itanium IA64 machines allows local users to cause a denial of service (system crash) via a 32-bit x86 application.

CVE-2009-3176 novell vulnerability CVSS: 9.3 11 Sep 2009, 20:30 UTC

Buffer overflow in the ActiveX control in Novell iPrint Client 4.38 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.1, "Novell iPrint Client 4.38 ActiveX exploit." NOTE: as of 20090909, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVE-2009-2848 novell vulnerability CVSS: 5.9 18 Aug 2009, 21:00 UTC

The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.

CVE-2009-2457 novell vulnerability CVSS: 5.0 14 Jul 2009, 20:30 UTC

The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP packet.

CVE-2009-2456 novell vulnerability CVSS: 5.0 14 Jul 2009, 20:30 UTC

The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wildcard characters in the Relative Distinguished Name (RDN).

CVE-2009-0192 novell vulnerability CVSS: 5.0 14 Jul 2009, 20:30 UTC

Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based buffer overflow.

CVE-2009-1636 novell vulnerability CVSS: 10.0 26 May 2009, 15:30 UTC

Multiple buffer overflows in the Internet Agent (aka GWIA) component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to execute arbitrary code via (1) a crafted e-mail address in an SMTP session or (2) an SMTP command.

CVE-2009-1634 novell vulnerability CVSS: 7.5 26 May 2009, 15:30 UTC

The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.

CVE-2009-1762 novell vulnerability CVSS: 4.3 22 May 2009, 16:48 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x before 7.03 HP2 allow remote attackers to inject arbitrary web script or HTML via the (1) GWAP.version or (2) User.Theme (aka User.Theme.index) parameter.

CVE-2009-1635 novell vulnerability CVSS: 4.3 22 May 2009, 16:48 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to inject arbitrary web script or HTML via (1) the User.lang parameter to the login page (aka gw/webacc), (2) style expressions in a message that contains an HTML file, or (3) vectors associated with incorrect protection mechanisms against scripting, as demonstrated using whitespace between JavaScript event names and values.

CVE-2009-1350 novell vulnerability CVSS: 10.0 21 Apr 2009, 16:24 UTC

Unspecified vulnerability in xtagent.exe in Novell NetIdentity Client before 1.2.4 allows remote attackers to execute arbitrary code by establishing an IPC$ connection to the XTIERRPCPIPE named pipe, and sending RPC messages that trigger a dereference of an arbitrary pointer.

CVE-2009-1294 novell vulnerability CVSS: 4.3 16 Apr 2009, 15:12 UTC

Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.

CVE-2009-1293 novell vulnerability CVSS: 5.0 16 Apr 2009, 15:12 UTC

The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.

CVE-2008-6722 novell vulnerability CVSS: 1.9 14 Apr 2009, 16:26 UTC

Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim's web-browser process that continues to send the original and valid SSL sessionID, related to inability of Apache Tomcat to clear entries from its SSL cache.

CVE-2009-0115 novell vulnerability CVSS: 7.2 30 Mar 2009, 16:30 UTC

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.

CVE-2009-0611 novell vulnerability CVSS: 4.3 17 Feb 2009, 17:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary web script or HTML via (1) the siteloc parameter in a displayaddsite action, the site parameter in a (2) generalproperties or (3) clusterserviceproperties action, (4) the adminurl parameter in a global action, or (5) the print-list parameter.

CVE-2009-0410 novell vulnerability CVSS: 10.0 03 Feb 2009, 19:30 UTC

Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command, leading to a buffer overflow.

CVE-2009-0274 novell vulnerability CVSS: 5.0 03 Feb 2009, 19:30 UTC

Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 might allow remote attackers to obtain sensitive information via a crafted URL, related to conversion of POST requests to GET requests.

CVE-2009-0273 novell vulnerability CVSS: 4.3 02 Feb 2009, 22:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allow remote attackers to inject arbitrary web script or HTML via the (1) User.id and (2) Library.queryText parameters to gw/webacc, and other vectors involving (3) HTML e-mail and (4) HTML attachments.

CVE-2009-0272 novell vulnerability CVSS: 6.8 02 Feb 2009, 22:30 UTC

Cross-site request forgery (CSRF) vulnerability in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allows remote attackers to insert e-mail forwarding rules, and modify unspecified other configuration settings, as arbitrary users via unknown vectors.

CVE-2008-5696 novell vulnerability CVSS: 9.3 19 Dec 2008, 18:30 UTC

Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.

CVE-2008-5231 novell vulnerability CVSS: 9.3 26 Nov 2008, 01:30 UTC

Stack-based buffer overflow in the ExecuteRequest method in the Novell iPrint ActiveX control in ienipp.ocx in Novell iPrint Client 5.06 and earlier allows remote attackers to execute arbitrary code via a long target-frame option value, a different vulnerability than CVE-2008-2431.

CVE-2008-2432 novell vulnerability CVSS: 5.0 26 Nov 2008, 01:30 UTC

Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell iPrint Client before 5.06 allows remote attackers to list the image files in an arbitrary directory via a directory name in the argument.

CVE-2008-2431 novell vulnerability CVSS: 9.3 26 Nov 2008, 01:30 UTC

Multiple buffer overflows in Novell iPrint Client before 5.06 allow remote attackers to execute arbitrary code by calling the Novell iPrint ActiveX control (aka ienipp.ocx) with (1) a long third argument to the GetDriverFile method; a long first argument to the (2) GetPrinterURLList or (3) GetPrinterURLList2 method; (4) a long argument to the GetFileList method; a long argument to the (5) GetServerVersion, (6) GetResourceList, or (7) DeleteResource method, related to nipplib.dll; a long uploadPath argument to the (8) UploadPrinterDriver or (9) UploadResource method, related to URIs; (10) a long seventh argument to the UploadResource method; a long string in the (11) second, (12) third, or (13) fourth argument to the GetDriverSettings method, related to the IppGetDriverSettings function in nipplib.dll; or (14) a long eighth argument to the UploadResourceToRMS method.

CVE-2008-5095 novell vulnerability CVSS: 4.3 14 Nov 2008, 19:20 UTC

Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2008-5094 novell vulnerability CVSS: 10.0 14 Nov 2008, 19:20 UTC

Heap-based buffer overflow in the NDS Service in Novell eDirectory before 8.8 SP3 has unknown impact and attack vectors.

CVE-2008-5093 novell vulnerability CVSS: 4.3 14 Nov 2008, 19:20 UTC

Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2008-5092 novell vulnerability CVSS: 10.0 14 Nov 2008, 19:20 UTC

Heap-based buffer overflows in Novell eDirectory HTTP protocol stack (HTTPSTK) before 8.8 SP3 have unknown impact and attack vectors related to the (1) HTTP language header and (2) HTTP content-length header.

CVE-2008-5091 novell vulnerability CVSS: 10.0 14 Nov 2008, 19:20 UTC

Buffer overflow in the LDAP Service in Novell eDirectory 8.7.3 before SP10a and 8.8 before SP3 allows attackers to cause a denial of service (application crash) via vectors involving an "invalid extensibleMatch filter."

CVE-2008-5073 novell vulnerability CVSS: 9.3 14 Nov 2008, 18:07 UTC

Heap-based buffer overflow in an ActiveX control in Novell ZENworks Desktop Management 6.5 allows remote attackers to execute arbitrary code via a long argument to the CanUninstall method.

CVE-2008-5021 novell vulnerability CVSS: 9.3 13 Nov 2008, 11:30 UTC

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.

CVE-2008-5038 novell vulnerability CVSS: 10.0 12 Nov 2008, 21:09 UTC

Use-after-free vulnerability in the NetWare Core Protocol (NCP) feature in Novell eDirectory 8.7.3 SP10 before 8.7.3 SP10 FTF1 and 8.8 SP2 for Windows allows remote attackers to cause a denial of service and possibly execute arbitrary code via a sequence of "Get NCP Extension Information By Name" requests that cause one thread to operate on memory after it has been freed in another thread, which triggers memory corruption, aka Novell Bug 373852.

CVE-2008-4480 novell vulnerability CVSS: 10.0 14 Oct 2008, 22:36 UTC

Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.x before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a crafted Netware Core Protocol opcode 0x24 message that triggers a calculation error that under-allocates a heap buffer.

CVE-2008-4479 novell vulnerability CVSS: 10.0 14 Oct 2008, 22:36 UTC

Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a SOAP request with a long Accept-Language header.

CVE-2008-4478 novell vulnerability CVSS: 10.0 14 Oct 2008, 22:36 UTC

Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbitrary code via a crafted (1) Content-Length header in a SOAP request or (2) Netware Core Protocol opcode 0x0F message, which triggers a heap-based buffer overflow.

CVE-2008-4047 novell vulnerability CVSS: 7.5 11 Sep 2008, 21:06 UTC

Unspecified vulnerability in Novell Forum (formerly SiteScape Forum) 7.0, 7.1, 7.2, 7.3, and 8.0 allows remote attackers to execute arbitrary TCL code via a modified URL. NOTE: this might overlap CVE-2007-6515.

CVE-2008-2436 novell vulnerability CVSS: 9.3 05 Sep 2008, 16:08 UTC

Multiple heap-based buffer overflows in the IppCreateServerRef function in nipplib.dll in Novell iPrint Client 4.x before 4.38 and 5.x before 5.08 allow remote attackers to execute arbitrary code via a long argument to the (1) GetPrinterURLList, (2) GetPrinterURLList2, or (3) GetFileList2 function in the Novell iPrint ActiveX control in ienipp.ocx.

CVE-2007-6716 novell vulnerability CVSS: 4.9 04 Sep 2008, 17:41 UTC

fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.

CVE-2008-3501 novell vulnerability CVSS: 4.3 06 Aug 2008, 18:41 UTC

Cross-site scripting (XSS) vulnerability in the WebAccess simple interface in Novell Groupwise 7.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2008-3488 novell vulnerability CVSS: 7.5 06 Aug 2008, 17:41 UTC

Unspecified vulnerability in Novell iManager before 2.7 SP1 (2.7.1) allows remote attackers to delete Plug-in Studio created Property Book Pages via unknown vectors.

CVE-2008-1809 novell vulnerability CVSS: 10.0 14 Jul 2008, 18:41 UTC

Heap-based buffer overflow in Novell eDirectory 8.7.3 before 8.7.3.10b, and 8.8 before 8.8.2 FTF2, allows remote attackers to execute arbitrary code via an LDAP search request containing "NULL search parameters."

CVE-2008-3159 novell vulnerability CVSS: 10.0 14 Jul 2008, 18:41 UTC

Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ftf2 allows remote attackers to execute arbitrary code via unspecified vectors that trigger a stack-based buffer overflow, related to "flawed arithmetic."

CVE-2008-3158 novell vulnerability CVSS: 6.9 11 Jul 2008, 22:41 UTC

Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory.

CVE-2008-2931 novell vulnerability CVSS: 7.2 09 Jul 2008, 18:41 UTC

The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.

CVE-2008-2812 novell vulnerability CVSS: 7.2 09 Jul 2008, 00:41 UTC

The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.

CVE-2008-0925 novell vulnerability CVSS: 4.3 18 Jun 2008, 19:41 UTC

Cross-site scripting (XSS) vulnerability in the iMonitor interface in Novell eDirectory 8.7.3.x before 8.7.3 sp10, and 8.8.x before 8.8.2 ftf2, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters that are used within "error messages of the HTTP stack."

CVE-2008-2703 novell vulnerability CVSS: 10.0 13 Jun 2008, 19:41 UTC

Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow remote attackers to execute arbitrary code via "spoofed server responses" that contain a long string after the NM_A_SZ_TRANSACTION_ID field name.

CVE-2008-2704 novell vulnerability CVSS: 5.0 13 Jun 2008, 19:41 UTC

Novell GroupWise Messenger (GWIM) before 2.0.3 Hot Patch 1 allows remote attackers to cause a denial of service (crash) via a long user ID, possibly involving a popup alert. NOTE: it is not clear whether this issue crosses privilege boundaries.

CVE-2008-2145 novell vulnerability CVSS: 7.2 12 May 2008, 19:20 UTC

Stack-based buffer overflow in Novell Client 4.91 SP4 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long username in the "forgotten password" dialog.

CVE-2008-2069 novell vulnerability CVSS: 9.3 02 May 2008, 23:20 UTC

Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI.

CVE-2008-1777 novell vulnerability CVSS: 5.0 14 Apr 2008, 16:05 UTC

The eDirectory Host Environment service (dhost.exe) in Novell eDirectory 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via a long HTTP HEAD request to TCP port 8028.

CVE-2008-1701 novell vulnerability CVSS: 5.0 08 Apr 2008, 18:05 UTC

Novell NetWare 6.5 allows attackers to cause a denial of service (ABEND) via a crafted Macintosh iPrint client request.

CVE-2008-0926 novell vulnerability CVSS: 7.5 28 Mar 2008, 18:44 UTC

The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.

CVE-2008-0924 novell vulnerability CVSS: 6.8 28 Mar 2008, 18:44 UTC

Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x series, allows remote attackers to cause a denial of service (daemon crash or CPU consumption) or execute arbitrary code via a long delRequest LDAP Extended Request message, probably involving a long Distinguished Name (DN) field.

CVE-2008-1330 novell vulnerability CVSS: 3.5 18 Mar 2008, 17:44 UTC

Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with the attacker.

CVE-2008-0935 novell vulnerability CVSS: 10.0 25 Feb 2008, 18:44 UTC

Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.34 allows remote attackers to execute arbitrary code via a long argument to the ExecuteRequest method.

CVE-2007-6701 novell vulnerability CVSS: 10.0 13 Feb 2008, 21:00 UTC

Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP4 for Windows allow remote attackers to execute arbitrary code via long arguments to multiple unspecified RPC functions, aka Novell bug 287919, a different vulnerability than CVE-2007-2954.

CVE-2008-0639 novell vulnerability CVSS: 10.0 13 Feb 2008, 21:00 UTC

Stack-based buffer overflow in the EnumPrinters function in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2, SP3, and SP4 for Windows allows remote attackers to execute arbitrary code via a crafted RPC request, aka Novell bug 353138, a different vulnerability than CVE-2006-5854. NOTE: this issue exists because of an incomplete fix for CVE-2007-6701.

CVE-2008-0731 novell vulnerability CVSS: 7.5 12 Feb 2008, 21:00 UTC

The Linux kernel before 2.6.18.8-0.8 in SUSE openSUSE 10.2 does not properly handle failure of an AppArmor change_hat system call, which might allow attackers to trigger the unconfining of an apparmored task.

CVE-2008-0663 novell vulnerability CVSS: 2.1 08 Feb 2008, 02:00 UTC

Novell Challenge Response Client (LCM) 2.7.5 and earlier, as used with Novell Client for Windows 4.91 SP4, allows users with physical access to a locked system to obtain contents of the clipboard by pasting the contents into the Challenge Question field.

CVE-2008-0525 novell vulnerability CVSS: 4.6 31 Jan 2008, 20:00 UTC

PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script.

CVE-2007-5762 novell vulnerability CVSS: 7.2 09 Jan 2008, 22:46 UTC

NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode.

CVE-2007-5665 novell vulnerability CVSS: 7.2 09 Jan 2008, 00:46 UTC

STEngine.exe 3.5.0.20 in Novell ZENworks Endpoint Security Management (ESM) 3.5, and other ESM versions before 3.5.0.82, dynamically creates scripts in a world-writable directory when generating diagnostic reports, which allows local users to gain privileges, as demonstrated by creating a cmd.exe binary in the diagnostic report directory.

CVE-2007-6625 novell vulnerability CVSS: 5.0 04 Jan 2008, 00:46 UTC

The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified network traffic that triggers a syslog message containing invalid format string specifiers, as demonstrated by a Nessus scan.

CVE-2007-6435 novell vulnerability CVSS: 9.3 18 Dec 2007, 20:46 UTC

Stack-based buffer overflow in Novell GroupWise before 6.5.7, when HTML preview of e-mail is enabled, allows user-assisted remote attackers to execute arbitrary code via a long SRC attribute in an IMG element when forwarding or replying to a crafted e-mail.

CVE-2007-6302 novell vulnerability CVSS: 6.8 10 Dec 2007, 19:46 UTC

Multiple heap-based buffer overflows in avirus.exe in Novell NetMail 3.5.2 before Messaging Architects M+NetMail 3.52f (aka 3.5.2F) allows remote attackers to execute arbitrary code via unspecified ASCII integers used as memory allocation arguments, aka "ZDI-CAN-162."

CVE-2007-5667 novell vulnerability CVSS: 7.2 14 Nov 2007, 01:46 UTC

NWFILTER.SYS in Novell Client 4.91 SP 1 through SP 4 for Windows 2000, XP, and Server 2003 makes the \.\nwfilter device available for arbitrary user-mode input via METHOD_NEITHER IOCTLs, which allows local users to gain privileges by passing a kernel address as an argument and overwriting kernel memory locations.

CVE-2007-5767 novell vulnerability CVSS: 10.0 02 Nov 2007, 23:46 UTC

Heap-based buffer overflow in the Client Trust application (clntrust.exe) in Novell BorderManager 3.8 before Update 1.5 allows remote attackers to execute arbitrary code via a validation request in which the Novell tree name is not properly delimited with a wide-character backslash or NULL character.

CVE-2007-5702 novell vulnerability CVSS: 4.3 29 Oct 2007, 22:46 UTC

Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions (aka the login box) in the Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.

CVE-2007-2954 novell vulnerability CVSS: 10.0 31 Aug 2007, 22:17 UTC

Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via certain long arguments to the (1) RpcAddPrinterDriver, (2) RpcGetPrinterDriverDirectory, and other unspecified RPC requests, aka Novell bug 300870, a different vulnerability than CVE-2006-5854.

CVE-2007-4557 novell vulnerability CVSS: 4.3 28 Aug 2007, 01:17 UTC

Cross-site scripting (XSS) vulnerability in the webacc servlet in Novell GroupWise 6.5 WebAccess allows remote attackers to inject arbitrary web script or HTML via the User.Id parameter, as demonstrated by a URL within a url field in a STYLE element, possibly due to an incomplete fix for CVE-2004-2103.2.

CVE-2007-4526 novell vulnerability CVSS: 2.1 25 Aug 2007, 00:17 UTC

The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file.

CVE-2007-4432 novell vulnerability CVSS: 4.6 20 Aug 2007, 19:17 UTC

Untrusted search path vulnerability in the wrapper scripts for the (1) rug, (2) zen-updater, (3) zen-installer, and (4) zen-remover programs on SUSE Linux 10.1 and Enterprise 10 allows local users to gain privileges via modified (a) LD_LIBRARY_PATH and (b) MONO_GAC_PREFIX environment variables.

CVE-2007-4394 novell vulnerability CVSS: 2.1 17 Aug 2007, 22:17 UTC

Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows local users to delete of arbitrary files via unknown vectors.

CVE-2007-3570 novell vulnerability CVSS: 7.5 05 Jul 2007, 19:30 UTC

The Linux Access Gateway in Novell Access Manager before 3.0 SP1 Release Candidate 1 (RC1) allows remote attackers to bypass unspecified security controls via Fullwidth/Halfwidth Unicode encoded data in a HTTP POST request.

CVE-2007-3571 novell vulnerability CVSS: 4.3 05 Jul 2007, 19:30 UTC

The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.

CVE-2007-2923 novell vulnerability CVSS: 9.3 18 Jun 2007, 10:30 UTC

The launch method in the LocalExec ActiveX control (LocalExec.ocx) in Novell exteNd Director 4.1 and Portal Services allows remote attackers to execute arbitrary commands.

CVE-2007-3207 novell vulnerability CVSS: 7.1 18 Jun 2007, 10:30 UTC

Buffer overflow in the NFS mount daemon (XNFS.NLM) in Novell NetWare 6.5 SP6, and probably earlier, allows remote attackers to cause a denial of service (abend) via a long path in a mount request.

CVE-2007-3200 novell vulnerability CVSS: 4.9 12 Jun 2007, 23:30 UTC

NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the admin username and password by reading this file.

CVE-2007-2513 novell vulnerability CVSS: 4.3 04 Jun 2007, 16:30 UTC

Novell GroupWise 7 before SP2 20070524, and GroupWise 6 before 6.5 post-SP6 20070522, allows remote attackers to obtain credentials via a man-in-the-middle attack.

CVE-2007-2616 novell vulnerability CVSS: 10.0 11 May 2007, 16:19 UTC

Stack-based buffer overflow in the SSL version of the NMDMC.EXE service in Novell NetMail 3.52e FTF2 and probably earlier allows remote attackers to execute arbitrary code via a crafted request.

CVE-2007-2476 novell vulnerability CVSS: 10.0 02 May 2007, 23:19 UTC

Unspecified vulnerability in Novell SecureLogin (NSL) 6 SP1 before 6.0.106 has unknown impact and remote attack vectors, related to Active Directory (AD) password changes.

CVE-2007-2475 novell vulnerability CVSS: 6.5 02 May 2007, 23:19 UTC

Unspecified vulnerability in the ADSCHEMA utility in Novell SecureLogin (NSL) 6 SP1 before 6.0.106 has unknown impact and remote attack vectors, related to granting "users excess permissions to their own attributes."

CVE-2006-4520 novell vulnerability CVSS: 7.8 30 Apr 2007, 22:19 UTC

ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before 8.8.1 FTF2, does not properly handle NCP fragments with a negative length, which allows remote attackers to cause a denial of service (daemon crash) when the heap is written to a log file.

CVE-2007-2171 novell vulnerability CVSS: 10.0 24 Apr 2007, 20:19 UTC

Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via long base64 content in an HTTP Basic Authentication request.

CVE-2007-1350 novell vulnerability CVSS: 6.8 08 Mar 2007, 22:19 UTC

Stack-based buffer overflow in webadmin.exe in Novell NetMail 3.5.2 allows remote attackers to execute arbitrary code via a long username during HTTP Basic authentication.

CVE-2006-7155 novell vulnerability CVSS: 7.5 07 Mar 2007, 20:19 UTC

Novell BorderManager 3.8 SP4 generates the same ISAKMP cookies for the same source IP and port number during the same day, which allows remote attackers to conduct denial of service and replay attacks. NOTE: this issue might be related to CVE-2006-5286.

CVE-2007-1309 novell vulnerability CVSS: 9.0 07 Mar 2007, 00:19 UTC

Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, then manually modifying policy.txt.

CVE-2007-1285 novell vulnerability CVSS: 5.0 06 Mar 2007, 20:19 UTC

The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.

CVE-2007-1119 novell vulnerability CVSS: 6.4 27 Feb 2007, 02:28 UTC

Unspecified vulnerability in Novell ZENworks 7 Desktop Management Support Pack 1 before Hot patch 3 (ZDM7SP1HP3) allows remote attackers to upload images to certain folders that were not configured in the "Only allow uploads to the following directories" setting via unspecified vectors.

CVE-2007-0110 novell vulnerability CVSS: 6.8 09 Jan 2007, 00:28 UTC

Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject arbitrary web script or HTML via the IssueInstant parameter, which is not properly handled in the resulting error message.

CVE-2007-0108 novell vulnerability CVSS: 6.0 09 Jan 2007, 00:28 UTC

nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.

CVE-2006-4220 novell vulnerability CVSS: 4.3 31 Dec 2006, 05:00 UTC

Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.

CVE-2006-6761 novell vulnerability CVSS: 6.5 27 Dec 2006, 02:28 UTC

Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via a long argument to the SUBSCRIBE command.

CVE-2006-6762 novell vulnerability CVSS: 4.0 27 Dec 2006, 02:28 UTC

The IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to cause a denial of service via an APPEND command with a single "(" (parenthesis) in the argument.

CVE-2006-6424 novell vulnerability CVSS: 9.0 27 Dec 2006, 01:28 UTC

Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow; and (2) via crafted arguments to the STOR command to the Network Messaging Application Protocol (NMAP) daemon, resulting in a stack overflow.

CVE-2006-6425 novell vulnerability CVSS: 9.0 27 Dec 2006, 01:28 UTC

Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via unspecified vectors involving the APPEND command.

CVE-2006-6675 novell vulnerability CVSS: 6.8 21 Dec 2006, 01:28 UTC

Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in Welcome web-app.

CVE-2006-6450 novell vulnerability CVSS: 7.5 10 Dec 2006, 21:28 UTC

Multiple SQL injection vulnerabilities in dagent/downloadreport.asp in Novell ZENworks Patch Management (ZPM) before 6.3.2.700 allow remote attackers to execute arbitrary SQL commands via the (1) agentid and (2) pass parameters.

CVE-2006-6443 novell vulnerability CVSS: 10.0 10 Dec 2006, 20:28 UTC

Buffer overflow in the Novell Distributed Print Services (NDPS) Print Provider for Windows component (NDPPNT.DLL) in Novell Client 4.91 has unknown impact and remote attack vectors.

CVE-2006-6299 novell vulnerability CVSS: 10.0 05 Dec 2006, 11:28 UTC

Integer overflow in Msg.dll in Novell ZENworks 7 Asset Management (ZAM) before SP1 IR11 and the Collection client allows remote attackers to execute arbitrary code via crafted packets, which trigger a heap-based buffer overflow.

CVE-2006-6307 novell vulnerability CVSS: 5.0 05 Dec 2006, 11:28 UTC

srvloc.sys in Novell Client for Windows before 4.91 SP3 allows remote attackers to cause an unspecified denial of service via a crafted packet to port 427 that triggers an access of pageable or invalid addresses using a higher interrupt request level (IRQL) than necessary.

CVE-2006-6306 novell vulnerability CVSS: 1.2 05 Dec 2006, 11:28 UTC

Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.

CVE-2006-5854 novell vulnerability CVSS: 7.5 03 Dec 2006, 19:28 UTC

Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitrary code via a long argument to the (1) EnumPrinters and (2) OpenPrinter functions.

CVE-2006-5814 novell vulnerability CVSS: 7.5 08 Nov 2006, 23:07 UTC

Unspecified vulnerability in Novell eDirectory allows remote attackers to execute arbitrary code, as demonstrated by vd_novell.pm, a "Novell eDirectory remote exploit." NOTE: As of 20061108, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.

CVE-2006-5813 novell vulnerability CVSS: 5.0 08 Nov 2006, 23:07 UTC

Unspecified vulnerability in Novell eDirectory 8.8 allows attackers to cause a denial of service, as demonstrated by vd_novell3.pm, a "Novell eDirectory 8.8 DoS." NOTE: As of 20061108, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.

CVE-2006-4521 novell vulnerability CVSS: 5.0 04 Nov 2006, 00:07 UTC

The BerDecodeLoginDataRequest function in the libnmasldap.so NMAS module in Novell eDirectory 8.8 and 8.8.1 before the Security Services 2.0.3 patch does not properly increment a pointer when handling certain input, which allows remote attackers to cause a denial of service (invalid memory access) via a crafted login request.

CVE-2006-4517 novell vulnerability CVSS: 7.8 01 Nov 2006, 15:07 UTC

Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP POST, which triggers a NULL pointer dereference.

CVE-2006-4177 novell vulnerability CVSS: 7.5 24 Oct 2006, 20:07 UTC

Heap-based buffer overflow in the NCP engine in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted NCP over IP packet that causes NCP to read more data than intended.

CVE-2006-5478 novell vulnerability CVSS: 7.5 24 Oct 2006, 20:07 UTC

Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute arbitrary code via (1) a long HTTP Host header, which triggers an overflow in the BuildRedirectURL function; or vectors related to a username containing a . (dot) character in the (2) SMTP, (3) POP, (4) IMAP, (5) HTTP, or (6) Networked Messaging Application Protocol (NMAP) Netmail services.

CVE-2006-5479 novell vulnerability CVSS: 5.0 24 Oct 2006, 20:07 UTC

The NCP Engine in Novell eDirectory before 8.7.3.8 FTF1 allows remote attackers to cause an unspecified denial of service via a certain "NCP Fragment."

CVE-2006-4509 novell vulnerability CVSS: 10.0 24 Oct 2006, 19:07 UTC

Integer overflow in the evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted request.

CVE-2006-4510 novell vulnerability CVSS: 10.0 24 Oct 2006, 19:07 UTC

The evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted request containing a value that is larger than the number of objects transmitted, which triggers an invalid free of unallocated memory.

CVE-2006-5286 novell vulnerability CVSS: 5.0 13 Oct 2006, 19:07 UTC

Unspecified vulnerability in IKE.NLM in Novell BorderManager 3.8 allows attackers to cause a denial of service (crash) via unknown attack vectors related to "VPN issues" for certain "IKE and IPsec settings."

CVE-2006-4511 novell vulnerability CVSS: 5.0 05 Oct 2006, 04:04 UTC

Messenger Agents (nmma.exe) in Novell GroupWise 2.0.2 and 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted HTTP POST request to TCP port 8300 with a modified val parameter, which triggers a null dereference related to "zero-size strings in blowfish routines."

CVE-2006-4185 novell vulnerability CVSS: 4.9 17 Aug 2006, 00:04 UTC

Unspecified vulnerability in the NCPENGINE in Novell eDirectory 8.7.3.8 allows local users to cause a denial of service (CPU consumption) via unspecified vectors, as originally demonstrated using a Nessus scan.

CVE-2006-4186 novell vulnerability CVSS: 2.1 17 Aug 2006, 00:04 UTC

The iManager in eMBoxClient.jar in Novell eDirectory 8.7.3.8 writes passwords in plaintext to a log file, which allows local users to obtain passwords by reading the file.

CVE-2006-3817 novell vulnerability CVSS: 4.3 11 Aug 2006, 10:04 UTC

Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrated by the "+ADw-SCRIPT+AD4-" sequence.

CVE-2006-3818 novell vulnerability CVSS: 4.3 11 Aug 2006, 10:04 UTC

Cross-site scripting (XSS) vulnerability in the login page in Novell GroupWise WebAccess 6.5 before 20060721 and WebAccess 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via the GWAP.version parameter.

CVE-2006-3697 novell vulnerability CVSS: 7.2 21 Jul 2006, 14:03 UTC

Agnitum Outpost Firewall Pro 3.51.759.6511 (462), as used in (1) Lavasoft Personal Firewall 1.0.543.5722 (433) and (2) Novell BorderManager Novell Client Firewall 2.0, does not properly restrict user activities in application windows that run in a LocalSystem context, which allows local users to gain privileges and execute commands (a) via the "open folder" option when no instance of explorer.exe is running, possibly related to the ShellExecute API function; or (b) by overwriting a batch file through the "Save Configuration As" option. NOTE: this might be a vulnerability in Microsoft Windows and explorer.exe instead of the firewall.

CVE-2006-3425 novell vulnerability CVSS: 7.5 07 Jul 2006, 00:05 UTC

FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.

CVE-2006-3430 novell vulnerability CVSS: 7.5 07 Jul 2006, 00:05 UTC

SQL injection vulnerability in checkprofile.asp in (1) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (2) Novell ZENworks 6.2 SR1 and earlier, allows remote attackers to execute arbitrary SQL commands via the agentid parameter.

CVE-2006-3426 novell vulnerability CVSS: 5.0 07 Jul 2006, 00:05 UTC

Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to dagent/nwupload.asp, which are used as pathname components.

CVE-2006-3268 novell vulnerability CVSS: 5.0 29 Jun 2006, 17:05 UTC

Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow users to obtain "random programmatic access" to other email within the same post office.

CVE-2006-2612 novell vulnerability CVSS: 2.1 26 May 2006, 01:06 UTC

Novell Client for Windows 4.8 and 4.9 does not restrict access to the clipboard contents while a machine is locked, which allows users with physical access to read the current clipboard contents by pasting them into the "User Name" field on the login prompt.

CVE-2006-2185 novell vulnerability CVSS: 4.0 22 May 2006, 17:02 UTC

PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password in cleartext to the abend.log log file when the groupOperationsMethod function fails, which allows context-dependent attackers to gain privileges.

CVE-2006-2496 novell vulnerability CVSS: 10.0 20 May 2006, 03:02 UTC

Buffer overflow in iMonitor 2.4 in Novell eDirectory 8.8 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown attack vectors.

CVE-2006-2327 novell vulnerability CVSS: 6.4 12 May 2006, 00:02 UTC

Multiple integer overflows in the DPRPC library (DPRPCNLM.NLM) NDPS/iPrint module in Novell Distributed Print Services in Novell NetWare 6.5 SP3, SP4, and SP5 allow remote attackers to execute arbitrary code via an XDR encoded array with a field that specifies a large number of elements, which triggers the overflows in the ndps_xdr_array function.

CVE-2006-2304 novell vulnerability CVSS: 10.0 11 May 2006, 10:02 UTC

Multiple integer overflows in the DPRPC library (DPRPCW32.DLL) in Novell Client 4.83 SP3, 4.90 SP2 and 4.91 SP2 allow remote attackers to execute arbitrary code via an XDR encoded array with a field that specifies a large number of elements, which triggers the overflows in the ndps_xdr_array function. NOTE: this was originally reported to be a buffer overflow by Novell, but the original cause is an integer overflow.

CVE-2006-0992 novell vulnerability CVSS: 10.0 14 Apr 2006, 10:02 UTC

Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon. NOTE: due to a typo, the original ZDI advisory accidentally referenced CVE-2006-0092. This is the correct identifier.

CVE-2006-0997 novell vulnerability CVSS: 5.0 23 Mar 2006, 11:06 UTC

The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic.

CVE-2006-0998 novell vulnerability CVSS: 5.0 23 Mar 2006, 11:06 UTC

The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) sometimes selects a weak cipher instead of an available stronger cipher, which makes it easier for remote attackers to sniff and decrypt an SSL protected session.

CVE-2006-0999 novell vulnerability CVSS: 5.0 23 Mar 2006, 11:06 UTC

The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) allows a client to force the server to use weak encryption by stating that a weak cipher is required for client compatibility, which might allow remote attackers to decrypt contents of an SSL protected session.

CVE-2006-1322 novell vulnerability CVSS: 5.0 20 Mar 2006, 22:02 UTC

Novell Netware NWFTPD 5.06.05 allows remote attackers to cause a denial of service (ABEND) via an MDTM command that uses a long path for the target file, possibly due to a buffer overflow.

CVE-2006-1218 novell vulnerability CVSS: 5.0 14 Mar 2006, 02:02 UTC

Unspecified vulnerability in the HTTP proxy in Novell BorderManager 3.8 and earlier allows remote attackers to cause a denial of service (CPU consumption and ABEND) via unknown attack vectors related to "media streaming over HTTP 1.1".

CVE-2006-0736 novell vulnerability CVSS: 10.0 27 Feb 2006, 20:06 UTC

Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2006-0803 novell vulnerability CVSS: 5.0 23 Feb 2006, 20:02 UTC

The signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is not intended for signature verification, which prevents YOU from detecting malicious scripts or code that do not pass the signature check when gpg 1.4.x is being used.

CVE-2005-1730 novell vulnerability CVSS: 9.3 31 Dec 2005, 05:00 UTC

Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.

CVE-2005-3655 novell vulnerability CVSS: 7.5 31 Dec 2005, 05:00 UTC

Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (novell-nrm) in Novell SUSE Linux Enterprise Server 9 allows remote attackers to execute arbitrary code via an HTTP POST request with a negative Content-Length parameter.

CVE-2005-4790 novell vulnerability CVSS: 6.9 31 Dec 2005, 05:00 UTC

Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.

CVE-2005-4791 novell vulnerability CVSS: 2.1 31 Dec 2005, 05:00 UTC

Multiple untrusted search path vulnerabilities in SUSE Linux 10.0 cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) liferea or (2) banshee.

CVE-2005-1976 novell vulnerability CVSS: 1.7 31 Dec 2005, 05:00 UTC

Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files.

CVE-2005-3786 novell vulnerability CVSS: 4.6 23 Nov 2005, 23:03 UTC

Novell ZENworks for Desktops 4.0.1, ZENworks for Servers 3.0.2, and ZENworks 6.5 Desktop Management does not restrict access to Remote Diagnostics, which allows local users to bypass security policies by using Console One.

CVE-2005-3314 novell vulnerability CVSS: 7.5 18 Nov 2005, 22:03 UTC

Stack-based buffer overflow in the IMAP daemon in Novell Netmail 3.5.2 allows remote attackers to execute arbitrary code via "long verb arguments."

CVE-2005-3315 novell vulnerability CVSS: 7.5 30 Oct 2005, 20:02 UTC

Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, and (4) computerFilter parameters to reports/default.asp.

CVE-2005-3321 novell vulnerability CVSS: 4.6 27 Oct 2005, 10:02 UTC

chkstat in SuSE Linux 9.0 through 10.0 allows local users to modify permissions of files by creating a hardlink to a file from a world-writable directory, which can cause the link count to drop to 1 when the file is deleted or replaced, which is then modified by chkstat to use weaker permissions.

CVE-2005-2469 novell vulnerability CVSS: 4.6 20 Oct 2005, 10:02 UTC

Stack-based buffer overflow in the NMAP Agent for Novell NetMail 3.52C and possibly earlier versions allows local users to execute arbitrary code via a long user name in the USER command.

CVE-2005-2804 novell vulnerability CVSS: 5.0 04 Oct 2005, 21:02 UTC

Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key.

CVE-2005-2852 novell vulnerability CVSS: 5.0 08 Sep 2005, 10:03 UTC

Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a denial of service (ABEND) via an incorrect password length, as exploited by the "worm.rbot.ccc" worm.

CVE-2005-2620 novell vulnerability CVSS: 5.0 17 Aug 2005, 04:00 UTC

grpWise.exe for Novell GroupWise client 5.5 through 6.5.2 stores the password in plaintext in memory, which allows attackers to obtain the password using a debugger or another mechanism to read process memory.

CVE-2005-2551 novell vulnerability CVSS: 7.5 12 Aug 2005, 04:00 UTC

Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.

CVE-2005-1761 novell vulnerability CVSS: 2.1 05 Aug 2005, 04:00 UTC

Linux kernel 2.6 and 2.4 on the IA64 architecture allows local users to cause a denial of service (kernel crash) via ptrace and the restore_sigcontext function.

CVE-2005-1767 novell vulnerability CVSS: 2.1 05 Aug 2005, 04:00 UTC

traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, which allows local users to cause a denial of service (oops and stack fault exception).

CVE-2005-2346 novell vulnerability CVSS: 7.5 03 Aug 2005, 04:00 UTC

Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in the Group Task section.

CVE-2005-2276 novell vulnerability CVSS: 4.3 26 Jul 2005, 04:00 UTC

Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "j&#X41vascript" in an IMG tag.

CVE-2005-2176 novell vulnerability CVSS: 6.4 09 Jul 2005, 04:00 UTC

Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

CVE-2005-1729 novell vulnerability CVSS: 5.0 12 Jun 2005, 04:00 UTC

Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1.

CVE-2005-1763 novell vulnerability CVSS: 7.2 09 Jun 2005, 04:00 UTC

Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory.

CVE-2005-1757 novell vulnerability CVSS: 7.5 08 Jun 2005, 04:00 UTC

Buffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code.

CVE-2005-1758 novell vulnerability CVSS: 7.5 08 Jun 2005, 04:00 UTC

Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code.

CVE-2005-1756 novell vulnerability CVSS: 4.3 08 Jun 2005, 04:00 UTC

Cross-site scripting (XSS) vulnerability in the ModWeb agent for Novell NetMail 3.52 before 3.52C allows remote attackers to inject arbitrary web script or HTML via calendar display fields.

CVE-2005-1543 novell vulnerability CVSS: 7.5 25 May 2005, 04:00 UTC

Multiple stack-based and heap-based buffer overflows in Remote Management authentication (zenrem32.exe) on Novell ZENworks 6.5 Desktop and Server Management, ZENworks for Desktops 4.x, ZENworks for Servers 3.x, and Remote Management allows remote attackers to execute arbitrary code via (1) unspecified vectors, (2) type 1 authentication requests, and (3) type 2 authentication requests.

CVE-2005-0744 novell vulnerability CVSS: 10.0 02 May 2005, 04:00 UTC

The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows attackers to hijack sessions and gain administrator privileges by (1) sniffing the connection on TCP port 51100 and replaying the authentication information or (2) obtaining and replaying the PCZQX02 authentication cookie from the browser.

CVE-2005-1040 novell vulnerability CVSS: 7.2 02 May 2005, 04:00 UTC

Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to "User input [being] passed to network scripts without verification."

CVE-2005-0746 novell vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.

CVE-2005-0819 novell vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start.

CVE-2005-1060 novell vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets.

CVE-2005-1065 novell vulnerability CVSS: 2.1 02 May 2005, 04:00 UTC

tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory.

CVE-2005-0798 novell vulnerability CVSS: 7.5 15 Mar 2005, 05:00 UTC

Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.

CVE-2005-0296 novell vulnerability CVSS: 5.0 17 Jan 2005, 05:00 UTC

NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page. NOTE: the vendor has disputed this issue

CVE-2004-2734 novell vulnerability CVSS: 10.0 31 Dec 2004, 05:00 UTC

webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.

CVE-2004-2314 novell vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

The Telnet listener for Novell iChain Server before 2.2 Field Patch 3b 2.2.116 does not have a password by default, which allows remote attackers to gain access.

CVE-2004-2579 novell vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

ACLCHECK module in Novell iChain 2.3 allows attackers to bypass access control rules of an unspecified component via an unspecified attack vector involving a string that contains escape sequences represented with "overlong UTF-8 encoding."

CVE-2004-2554 novell vulnerability CVSS: 7.2 31 Dec 2004, 05:00 UTC

Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.

CVE-2004-2298 novell vulnerability CVSS: 6.4 31 Dec 2004, 05:00 UTC

Novell Internet Messaging System (NIMS) 2.6 and 3.0, and NetMail 3.1 and 3.5, is installed with a default NMAP authentication credential, which allows remote attackers to read and write mail store data if the administrator does not change the credential by using the NMAP Credential Generator.

CVE-2004-2580 novell vulnerability CVSS: 5.8 31 Dec 2004, 05:00 UTC

Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via unspecified vectors.

CVE-2004-1457 novell vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

The Virtual Private Network (VPN) capability in Novell Bordermanager 3.8 allows remote attackers to cause a denial of service (ABEND in IKE.NLM) via a malformed IKE packet, as sent by the Striker ISAKMP Protocol Test Suite.

CVE-2004-2104 novell vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.

CVE-2004-2105 novell vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt files via a full pathname in the error parameter.

CVE-2004-2106 novell vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3) /com/novell/webaccess, or (4) /ns-icons/.

CVE-2004-2581 novell vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

Novell iChain 2.3 allows attackers to cause a denial of service via a URL with a "specific string."

CVE-2004-2582 novell vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

Novell iChain 2.3 includes the build number in the VIA line of the proxy server's HTTP headers, which allows remote attackers to obtain sensitive information.

CVE-2004-2103 novell vulnerability CVSS: 4.3 31 Dec 2004, 05:00 UTC

Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version parameter to webacc, or (4) a URL request for a .bas file with script in the filename.

CVE-2004-2757 novell vulnerability CVSS: 4.3 31 Dec 2004, 05:00 UTC

Cross-site scripting (XSS) vulnerability in the failed login page in Novell iChain before 2.2 build 2.2.113 and 2.3 First Customer Ship (FCS) allows remote attackers to inject arbitrary web script or HTML via url parameter.

CVE-2004-2414 novell vulnerability CVSS: 2.1 31 Dec 2004, 05:00 UTC

Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.

CVE-2004-0079 novell vulnerability CVSS: 5.0 23 Nov 2004, 05:00 UTC

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

CVE-2004-0081 novell vulnerability CVSS: 5.0 23 Nov 2004, 05:00 UTC

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

CVE-2004-0112 novell vulnerability CVSS: 5.0 23 Nov 2004, 05:00 UTC

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

CVE-2005-1247 novell vulnerability CVSS: 5.0 15 Jan 2004, 05:00 UTC

webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exploit for the OpenSSL ASN.1 parsing vulnerability.

CVE-2003-1551 novell vulnerability CVSS: 10.0 31 Dec 2003, 05:00 UTC

Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."

CVE-2003-0976 novell vulnerability CVSS: 7.5 15 Dec 2003, 05:00 UTC

NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount file systems when XNFS should deny the host.

CVE-2003-1150 novell vulnerability CVSS: 7.5 27 Oct 2003, 05:00 UTC

Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors.

CVE-2003-0636 novell vulnerability CVSS: 7.5 27 Aug 2003, 04:00 UTC

Novell iChain 2.2 before Support Pack 1 does not properly verify that URL redirects match the DNS name of an accelerator, which allows attackers to redirect URLs to malicious web sites.

CVE-2003-0638 novell vulnerability CVSS: 7.5 27 Aug 2003, 04:00 UTC

Multiple buffer overflows in Novell iChain 2.1 before Field Patch 3, and iChain 2.2 before Field Patch 1a, allow attackers to cause a denial of service (ABEND) and possibly execute arbitrary code via (1) a long user name or (2) an unknown attack related to a "special script against login."

CVE-2003-0562 novell vulnerability CVSS: 5.0 27 Aug 2003, 04:00 UTC

Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.

CVE-2003-0635 novell vulnerability CVSS: 5.0 27 Aug 2003, 04:00 UTC

Unknown vulnerability or vulnerabilities in Novell iChain 2.2 before Support Pack 1, with unknown impact, possibly related to unauthorized access to (1) NCPIP.NLM and (2) JSTCP.NLM.

CVE-2003-0637 novell vulnerability CVSS: 5.0 27 Aug 2003, 04:00 UTC

Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess usernames and conduct brute force password guessing.

CVE-2003-0639 novell vulnerability CVSS: 5.0 27 Aug 2003, 04:00 UTC

Unknown vulnerability in Novell iChain 2.2 before Support Pack 1 allows users to access restricted or secure pages without authentication.

CVE-2002-1413 novell vulnerability CVSS: 7.5 11 Apr 2003, 04:00 UTC

RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection.

CVE-2002-1436 novell vulnerability CVSS: 7.5 11 Apr 2003, 04:00 UTC

The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.

CVE-2002-1417 novell vulnerability CVSS: 5.0 11 Apr 2003, 04:00 UTC

Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL containing a "..%5c" sequence (modified dot-dot), which is mapped to the directory separator.

CVE-2002-1418 novell vulnerability CVSS: 5.0 11 Apr 2003, 04:00 UTC

Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to cause a denial of service (ABEND) via a long module name.

CVE-2002-1437 novell vulnerability CVSS: 5.0 11 Apr 2003, 04:00 UTC

Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.

CVE-2002-1438 novell vulnerability CVSS: 5.0 11 Apr 2003, 04:00 UTC

The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option.

CVE-2002-1552 novell vulnerability CVSS: 7.5 31 Mar 2003, 05:00 UTC

Novell eDirectory (eDir) 8.6.2 and Netware 5.1 eDir 85.x allows users with expired passwords to gain inappropriate permissions when logging in from Remote Manager.

CVE-2002-2096 novell vulnerability CVSS: 7.5 31 Dec 2002, 05:00 UTC

Buffer overflow in Novell Remote Manager module, httpstk.nlm, in NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary code via a long (1) username or (2) password.

CVE-2002-2119 novell vulnerability CVSS: 7.5 31 Dec 2002, 05:00 UTC

Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing.

CVE-2002-1634 novell vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3) websinfo.bas, (4) ndslogin.pl, (5) volscgi.pl, (6) lancgi.pl, (7) test.jse, or (8) env.pl.

CVE-2002-1772 novell vulnerability CVSS: 4.6 31 Dec 2002, 05:00 UTC

Novell Netware 5.0 through 5.1 may allow local users to gain "Domain Admin" rights by logging into a Novell Directory Services (NDS) account, and executing "net use" on an NDS_ADM account that is not in the NT domain but has domain access rights, which allows the user to enter a null password.

CVE-2002-1754 novell vulnerability CVSS: 2.1 31 Dec 2002, 05:00 UTC

Buffer overflow in Novell NetWare Client 4.80 through 4.83 allows local users to cause a denial of service (crash) by using ping, traceroute, or a similar utility to force the client to resolve a large hostname.

CVE-2002-2083 novell vulnerability CVSS: 2.1 31 Dec 2002, 05:00 UTC

The Novell Netware client running on Windows 95 allows local users to bypass the login and open arbitrary files via the "What is this?" help feature, which can be launched from the Novell Netware login screen.

CVE-2002-1283 novell vulnerability CVSS: 5.0 29 Nov 2002, 05:00 UTC

Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute.

CVE-2002-0996 novell vulnerability CVSS: 7.5 04 Oct 2002, 04:00 UTC

Multiple buffer overflows in Novell NetMail (NIMS) 3.0.3 before 3.0.3C allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) WebAdmin or (2) ModWeb.

CVE-2002-1088 novell vulnerability CVSS: 7.5 04 Oct 2002, 04:00 UTC

Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.

CVE-2002-0929 novell vulnerability CVSS: 5.0 04 Oct 2002, 04:00 UTC

Buffer overflows in the DHCP server for NetWare 6.0 SP1 allow remote attackers to cause a denial of service (reboot) via long DHCP requests.

CVE-2002-0930 novell vulnerability CVSS: 5.0 04 Oct 2002, 04:00 UTC

Format string vulnerability in the FTP server for Novell Netware 6.0 SP1 (NWFTPD) allows remote attackers to cause a denial of service (ABEND) via format strings in the USER command.

CVE-2002-0997 novell vulnerability CVSS: 5.0 04 Oct 2002, 04:00 UTC

Buffer overflows in IMAP Agent (imapd) for Novell NetMail (NIMS) 3.0.3 before 3.0.3A allows remote attackers to cause a denial of service.

CVE-2002-1002 novell vulnerability CVSS: 5.0 04 Oct 2002, 04:00 UTC

Buffer overflow in Novell iManager (eMFrame 1.2.1) allows remote attackers to cause a denial of service (crash) via a long user name.

CVE-2002-0530 novell vulnerability CVSS: 5.1 12 Aug 2002, 04:00 UTC

Cross-site scripting vulnerability in Novell Web Search 2.0.1 allows remote attackers to execute arbitrary script as other Web Search users via the search parameter.

CVE-2002-0779 novell vulnerability CVSS: 5.0 12 Aug 2002, 04:00 UTC

FTP proxy server for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service (network connectivity loss) via a connection to port 21 with a large amount of random data.

CVE-2002-0780 novell vulnerability CVSS: 5.0 12 Aug 2002, 04:00 UTC

IP/IPX gateway for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a connection to port 8225 with a large amount of random data, which causes ipipxgw.nlm to ABEND.

CVE-2002-0781 novell vulnerability CVSS: 5.0 12 Aug 2002, 04:00 UTC

RTSP proxy for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a GET request to port 9090 followed by a series of carriage returns, which causes proxy.nlm to ABEND.

CVE-2002-0782 novell vulnerability CVSS: 5.0 12 Aug 2002, 04:00 UTC

Novell BorderManager 3.5 with PAT (Port-Address Translate) enabled allows remote attackers to cause a denial of service by filling the connection table with a large number of connection requests to hosts that do not have a specific route, which may be forwarded to the public interface.

CVE-2002-0791 novell vulnerability CVSS: 5.0 12 Aug 2002, 04:00 UTC

Novell Netware FTP server NWFTPD before 5.02r allows remote attackers to cause a denial of service (CPU consumption) via a connection to the server followed by a carriage return, and possibly other invalid commands with improper syntax or length.

CVE-2002-0341 novell vulnerability CVSS: 5.0 25 Jun 2002, 04:00 UTC

GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.

CVE-2002-0303 novell vulnerability CVSS: 4.6 31 May 2002, 04:00 UTC

GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.

CVE-1999-1081 novell vulnerability CVSS: 5.0 15 Jan 2002, 05:00 UTC

Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.

CVE-2001-1580 novell vulnerability CVSS: 5.0 31 Dec 2001, 05:00 UTC

Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows remote attackers to read arbitrary files via ".." sequences in the query string.

CVE-2001-1195 novell vulnerability CVSS: 7.5 15 Dec 2001, 05:00 UTC

Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges.

CVE-2001-1458 novell vulnerability CVSS: 5.0 15 Oct 2001, 04:00 UTC

Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.

CVE-2001-1231 novell vulnerability CVSS: 5.0 14 Aug 2001, 04:00 UTC

GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.

CVE-2001-1232 novell vulnerability CVSS: 5.0 14 Aug 2001, 04:00 UTC

GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".

CVE-2001-1233 novell vulnerability CVSS: 5.0 14 Aug 2001, 04:00 UTC

Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.

CVE-2001-0486 novell vulnerability CVSS: 5.0 02 Jul 2001, 04:00 UTC

Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353.

CVE-2001-0355 novell vulnerability CVSS: 5.0 27 Jun 2001, 04:00 UTC

Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementation error in Groupwise system policies.

CVE-1999-0805 novell vulnerability CVSS: 5.0 12 Mar 2001, 05:00 UTC

Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests.

CVE-2000-0793 novell vulnerability CVSS: 10.0 20 Oct 2000, 04:00 UTC

Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system.

CVE-2000-0669 novell vulnerability CVSS: 5.0 11 Jul 2000, 04:00 UTC

Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.

CVE-2000-0651 novell vulnerability CVSS: 7.5 07 Jul 2000, 04:00 UTC

The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine.

CVE-2000-0591 novell vulnerability CVSS: 5.0 05 Jul 2000, 04:00 UTC

Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL.

CVE-2000-0600 novell vulnerability CVSS: 7.5 26 Jun 2000, 04:00 UTC

Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL.

CVE-2000-0257 novell vulnerability CVSS: 7.5 19 Apr 2000, 04:00 UTC

Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.

CVE-2000-0152 novell vulnerability CVSS: 5.0 30 Mar 2000, 05:00 UTC

Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connection to port 2000.

CVE-2000-0146 novell vulnerability CVSS: 5.0 07 Feb 2000, 05:00 UTC

The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet.

CVE-1999-1307 novell vulnerability CVSS: 7.2 31 Dec 1999, 05:00 UTC

Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.

CVE-1999-1382 novell vulnerability CVSS: 7.2 31 Dec 1999, 05:00 UTC

NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to "Read Only," which NetWare-NFS changes to a setuid root program.

CVE-1999-1320 novell vulnerability CVSS: 4.6 31 Dec 1999, 05:00 UTC

Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing.

CVE-1999-1005 novell vulnerability CVSS: 5.0 19 Dec 1999, 05:00 UTC

Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.

CVE-1999-1006 novell vulnerability CVSS: 5.0 19 Dec 1999, 05:00 UTC

Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.

CVE-1999-1086 novell vulnerability CVSS: 10.0 15 Jul 1999, 04:00 UTC

Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls.

CVE-1999-0929 novell vulnerability CVSS: 5.0 16 Jun 1999, 04:00 UTC

Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.

CVE-1999-0470 novell vulnerability CVSS: 5.0 09 Apr 1999, 04:00 UTC

A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.

CVE-1999-1020 novell vulnerability CVSS: 7.5 18 Sep 1998, 04:00 UTC

The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.

CVE-1999-0524 novell vulnerability CVSS: 2.1 01 Aug 1997, 04:00 UTC

ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.

CVE-1999-0265 novell vulnerability CVSS: 5.0 01 Jan 1997, 05:00 UTC

ICMP redirect messages may crash or lock up a host.

CVE-1999-0175 novell vulnerability CVSS: 5.0 01 Jul 1996, 04:00 UTC

The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.

CVE-1999-1215 novell vulnerability CVSS: 4.6 16 Sep 1993, 04:00 UTC

LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges.