Skip to main content

Vendor archive

novell CVEs

Beta · best-effort

665 CVEs tagged to vendor novell156 Critical, 165 High, 313 Medium, 31 Low, 0 Unrated.

CVE-2009-0895

Published Dec 3, 2009

Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containin…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3863

Published Nov 4, 2009

Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argumen…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3862

Published Nov 4, 2009

The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote at…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1297

Published Oct 23, 2009

iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitr…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2707

Published Sep 18, 2009

Unspecified vulnerability in ia32el (aka the IA 32 emulation functionality) before 7042_7022-0.4.2 in SUSE Linux Enterprise (SLE) 10 SP2 on Itanium IA64 machines allows local user…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3176

Published Sep 11, 2009

Buffer overflow in the ActiveX control in Novell iPrint Client 4.38 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown at…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2848

Published Aug 18, 2009

The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial…

CVSS 5.9 · Medium

CVE-2009-2457

Published Jul 14, 2009

The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP packet.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2456

Published Jul 14, 2009

The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wil…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0192

Published Jul 14, 2009

Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP re…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1636

Published May 26, 2009

Multiple buffer overflows in the Internet Agent (aka GWIA) component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to execute arbitrary cod…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1634

Published May 26, 2009

The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1762

Published May 22, 2009

Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x before 7.03 HP2 allow remote attackers to inject arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1635

Published May 22, 2009

Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to inject arbi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1350

Published Apr 21, 2009

Unspecified vulnerability in xtagent.exe in Novell NetIdentity Client before 1.2.4 allows remote attackers to execute arbitrary code by establishing an IPC$ connection to the XTIE…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1293

Published Apr 16, 2009

The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the username is valid or invalid, wh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6722

Published Apr 14, 2009

Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim's web-…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0115

Published Mar 30, 2009

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly o…

CVSS 7.8 · High

CVE-2009-0611

Published Feb 17, 2009

Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0410

Published Feb 3, 2009

Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0274

Published Feb 3, 2009

Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 might allow remote attackers to obtain sensitive information via a crafte…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 665 CVEsPage 17 of 27