Skip to main content

Vendor archive

novell CVEs

Beta · best-effort

665 CVEs tagged to vendor novell156 Critical, 165 High, 313 Medium, 31 Low, 0 Unrated.

CVE-2007-6625

Published Jan 4, 2008

The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon cra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6435

Published Dec 18, 2007

Stack-based buffer overflow in Novell GroupWise before 6.5.7, when HTML preview of e-mail is enabled, allows user-assisted remote attackers to execute arbitrary code via a long SR…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6302

Published Dec 10, 2007

Multiple heap-based buffer overflows in avirus.exe in Novell NetMail 3.5.2 before Messaging Architects M+NetMail 3.52f (aka 3.5.2F) allows remote attackers to execute arbitrary co…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5767

Published Nov 2, 2007

Heap-based buffer overflow in the Client Trust application (clntrust.exe) in Novell BorderManager 3.8 before Update 1.5 allows remote attackers to execute arbitrary code via a val…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5702

Published Oct 29, 2007

Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions (aka the login box) in the Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x allows r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2954

Published Aug 31, 2007

Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4557

Published Aug 28, 2007

Cross-site scripting (XSS) vulnerability in the webacc servlet in Novell GroupWise 6.5 WebAccess allows remote attackers to inject arbitrary web script or HTML via the User.Id par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4432

Published Aug 20, 2007

Untrusted search path vulnerability in the wrapper scripts for the (1) rug, (2) zen-updater, (3) zen-installer, and (4) zen-remover programs on SUSE Linux 10.1 and Enterprise 10 a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4394

Published Aug 17, 2007

Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows loca…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-3570

Published Jul 5, 2007

The Linux Access Gateway in Novell Access Manager before 3.0 SP1 Release Candidate 1 (RC1) allows remote attackers to bypass unspecified security controls via Fullwidth/Halfwidth…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3571

Published Jul 5, 2007

The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-He…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2923

Published Jun 18, 2007

The launch method in the LocalExec ActiveX control (LocalExec.ocx) in Novell exteNd Director 4.1 and Portal Services allows remote attackers to execute arbitrary commands.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-3207

Published Jun 18, 2007

Buffer overflow in the NFS mount daemon (XNFS.NLM) in Novell NetWare 6.5 SP6, and probably earlier, allows remote attackers to cause a denial of service (abend) via a long path in…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3200

Published Jun 12, 2007

NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the a…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2513

Published Jun 4, 2007

Novell GroupWise 7 before SP2 20070524, and GroupWise 6 before 6.5 post-SP6 20070522, allows remote attackers to obtain credentials via a man-in-the-middle attack.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2616

Published May 11, 2007

Stack-based buffer overflow in the SSL version of the NMDMC.EXE service in Novell NetMail 3.52e FTF2 and probably earlier allows remote attackers to execute arbitrary code via a c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-2475

Published May 2, 2007

Unspecified vulnerability in the ADSCHEMA utility in Novell SecureLogin (NSL) 6 SP1 before 6.0.106 has unknown impact and remote attack vectors, related to granting "users excess…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2476

Published May 2, 2007

Unspecified vulnerability in Novell SecureLogin (NSL) 6 SP1 before 6.0.106 has unknown impact and remote attack vectors, related to Active Directory (AD) password changes.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-4520

Published Apr 30, 2007

ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before 8.8.1 FTF2, does not properly handle NCP fragments with a negative length, which allows remote attackers to cause a den…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2171

Published Apr 24, 2007

Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via lo…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1350

Published Mar 8, 2007

Stack-based buffer overflow in webadmin.exe in Novell NetMail 3.5.2 allows remote attackers to execute arbitrary code via a long username during HTTP Basic authentication.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7155

Published Mar 7, 2007

Novell BorderManager 3.8 SP4 generates the same ISAKMP cookies for the same source IP and port number during the same day, which allows remote attackers to conduct denial of servi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 665 CVEsPage 20 of 27