Skip to main content

Vendor/product archive

novell / imanager CVEs

Beta · best-effort

13 CVEs tagged to novell / imanager4 Critical, 5 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2017-7432

Published May 3, 2017

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7430

Published May 3, 2017

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3268

Published Apr 24, 2013

Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-1088

Published Apr 24, 2013

Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging imp…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4188

Published Apr 9, 2012

Buffer overflow in the Create Attribute function in jclient in Novell iManager 2.7.4 before patch 4 allows remote authenticated users to cause a denial of service (application cra…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1930

Published Jun 28, 2010

Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree parameter in a login request to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1929

Published Jun 28, 2010

Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, an…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4486

Published Jan 8, 2010

Stack-based buffer overflow in the eDirectory plugin in Novell iManager before 2.7.3 allows remote attackers to execute arbitrary code via vectors that trigger long arguments to a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3488

Published Aug 6, 2008

Unspecified vulnerability in Novell iManager before 2.7 SP1 (2.7.1) allows remote attackers to delete Plug-in Studio created Property Book Pages via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4517

Published Nov 1, 2006

Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP POST, which triggers a NULL po…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1730

Published Dec 31, 2005

Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1