Skip to main content

Vendor archive

novell CVEs

Beta · best-effort

665 CVEs tagged to vendor novell156 Critical, 165 High, 313 Medium, 31 Low, 0 Unrated.

CVE-2007-1309

Published Mar 7, 2007

Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, then manually modifying policy…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1119

Published Feb 27, 2007

Unspecified vulnerability in Novell ZENworks 7 Desktop Management Support Pack 1 before Hot patch 3 (ZDM7SP1HP3) allows remote attackers to upload images to certain folders that w…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0108

Published Jan 9, 2007

nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0110

Published Jan 9, 2007

Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject arbitrary web script or HTML…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4220

Published Dec 31, 2006

Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web scri…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6761

Published Dec 27, 2006

Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via a long argument to the S…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6762

Published Dec 27, 2006

The IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to cause a denial of service via an APPEND command with a single "(" (parenthesis) in…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6424

Published Dec 27, 2006

Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying comm…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6425

Published Dec 27, 2006

Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via unspecified vectors invo…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6675

Published Dec 21, 2006

Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or H…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6450

Published Dec 10, 2006

Multiple SQL injection vulnerabilities in dagent/downloadreport.asp in Novell ZENworks Patch Management (ZPM) before 6.3.2.700 allow remote attackers to execute arbitrary SQL comm…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6443

Published Dec 10, 2006

Buffer overflow in the Novell Distributed Print Services (NDPS) Print Provider for Windows component (NDPPNT.DLL) in Novell Client 4.91 has unknown impact and remote attack vector…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6299

Published Dec 5, 2006

Integer overflow in Msg.dll in Novell ZENworks 7 Asset Management (ZAM) before SP1 IR11 and the Collection client allows remote attackers to execute arbitrary code via crafted pac…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6306

Published Dec 5, 2006

Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory conte…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6307

Published Dec 5, 2006

srvloc.sys in Novell Client for Windows before 4.91 SP3 allows remote attackers to cause an unspecified denial of service via a crafted packet to port 427 that triggers an access…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5854

Published Dec 3, 2006

Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitrary code via a long argument…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5813

Published Nov 8, 2006

Unspecified vulnerability in Novell eDirectory 8.8 allows attackers to cause a denial of service, as demonstrated by vd_novell3.pm, a "Novell eDirectory 8.8 DoS." NOTE: As of 2006…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5814

Published Nov 8, 2006

Unspecified vulnerability in Novell eDirectory allows remote attackers to execute arbitrary code, as demonstrated by vd_novell.pm, a "Novell eDirectory remote exploit." NOTE: As o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4521

Published Nov 4, 2006

The BerDecodeLoginDataRequest function in the libnmasldap.so NMAS module in Novell eDirectory 8.8 and 8.8.1 before the Security Services 2.0.3 patch does not properly increment a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4517

Published Nov 1, 2006

Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP POST, which triggers a NULL po…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4177

Published Oct 24, 2006

Heap-based buffer overflow in the NCP engine in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted NCP over IP packet that causes…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5478

Published Oct 24, 2006

Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5479

Published Oct 24, 2006

The NCP Engine in Novell eDirectory before 8.7.3.8 FTF1 allows remote attackers to cause an unspecified denial of service via a certain "NCP Fragment."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4509

Published Oct 24, 2006

Integer overflow in the evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 501-525 of 665 CVEsPage 21 of 27