Skip to main content

Vendor archive

novell CVEs

Beta · best-effort

665 CVEs tagged to vendor novell156 Critical, 165 High, 313 Medium, 31 Low, 0 Unrated.

CVE-2009-0273

Published Feb 2, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allow remote attackers to inject arbitrary web sc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0272

Published Feb 2, 2009

Cross-site request forgery (CSRF) vulnerability in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allows remote attackers to insert e-mail forwarding r…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5696

Published Dec 19, 2008

Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote at…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5231

Published Nov 26, 2008

Stack-based buffer overflow in the ExecuteRequest method in the Novell iPrint ActiveX control in ienipp.ocx in Novell iPrint Client 5.06 and earlier allows remote attackers to exe…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2432

Published Nov 26, 2008

Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell iPrint Client before 5.06 allows remote attackers to list the image files in an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2431

Published Nov 26, 2008

Multiple buffer overflows in Novell iPrint Client before 5.06 allow remote attackers to execute arbitrary code by calling the Novell iPrint ActiveX control (aka ienipp.ocx) with (…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5094

Published Nov 14, 2008

Heap-based buffer overflow in the NDS Service in Novell eDirectory before 8.8 SP3 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5093

Published Nov 14, 2008

Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5092

Published Nov 14, 2008

Heap-based buffer overflows in Novell eDirectory HTTP protocol stack (HTTPSTK) before 8.8 SP3 have unknown impact and attack vectors related to the (1) HTTP language header and (2…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5091

Published Nov 14, 2008

Buffer overflow in the LDAP Service in Novell eDirectory 8.7.3 before SP10a and 8.8 before SP3 allows attackers to cause a denial of service (application crash) via vectors involv…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5073

Published Nov 14, 2008

Heap-based buffer overflow in an ActiveX control in Novell ZENworks Desktop Management 6.5 allows remote attackers to execute arbitrary code via a long argument to the CanUninstal…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5021

Published Nov 13, 2008

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial…

CVSS 9.3 · Critical

CVE-2008-5038

Published Nov 12, 2008

Use-after-free vulnerability in the NetWare Core Protocol (NCP) feature in Novell eDirectory 8.7.3 SP10 before 8.7.3 SP10 FTF1 and 8.8 SP2 for Windows allows remote attackers to c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4480

Published Oct 14, 2008

Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.x before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a crafted Netw…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4479

Published Oct 14, 2008

Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a SOAP request…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4478

Published Oct 14, 2008

Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbitrary code via a crafted (1) Co…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4047

Published Sep 11, 2008

Unspecified vulnerability in Novell Forum (formerly SiteScape Forum) 7.0, 7.1, 7.2, 7.3, and 8.0 allows remote attackers to execute arbitrary TCL code via a modified URL. NOTE: t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2436

Published Sep 5, 2008

Multiple heap-based buffer overflows in the IppCreateServerRef function in nipplib.dll in Novell iPrint Client 4.x before 4.38 and 5.x before 5.08 allow remote attackers to execut…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3501

Published Aug 6, 2008

Cross-site scripting (XSS) vulnerability in the WebAccess simple interface in Novell Groupwise 7.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3488

Published Aug 6, 2008

Unspecified vulnerability in Novell iManager before 2.7 SP1 (2.7.1) allows remote attackers to delete Plug-in Studio created Property Book Pages via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 665 CVEsPage 18 of 27