Search: "novell"

464 CVEs found

Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted iprint-client-config-info parameter in a printer-url.

Published: 2011-06-09
Products: 20
Vendors:
novell

Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs parameter in a printer-url.

Published: 2011-06-09
Products: 20
Vendors:
novell

Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs cookie.

Published: 2011-06-09
Products: 20
Vendors:
novell
CVE-2011-2220
10.0 HIGH

Stack-based buffer overflow in NFREngine.exe in Novell File Reporter Engine before 1.0.2.53, as used in Novell File Reporter and other products, allows remote attackers to execute arbitrary code via a...

Published: 2011-07-14
Products: 2
Vendors:
novell
CVE-2011-2750
5.0 MEDIUM

NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.

Published: 2011-07-17
Products: 4
Vendors:
novell
CVE-2011-2221
5.0 MEDIUM

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and obtain sensitive GroupWise information via unspecifie...

Published: 2011-08-09
Products: 8
Vendors:
novell
CVE-2011-2222
4.3 MEDIUM

Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vector...

Published: 2011-08-09
Products: 8
Vendors:
novell
CVE-2011-2223
5.0 MEDIUM

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffi...

Published: 2011-08-09
Products: 8
Vendors:
novell
CVE-2011-2224
4.3 MEDIUM

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cr...

Published: 2011-08-09
Products: 8
Vendors:
novell
CVE-2011-3013
5.0 MEDIUM

WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for remote attackers to obtain access via a brute-forc...

Published: 2011-08-09
Products: 8
Vendors:
novell
CVE-2011-3014
5.0 MEDIUM

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not properly restrict caching of HTTPS responses, which makes it easier for remote attackers to obtain sensiti...

Published: 2011-08-09
Products: 8
Vendors:
novell

The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that...

Published: 2011-09-06
Products: 3
Vendors:
novell
CVE-2011-0333
10.0 HIGH

Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitr...

Published: 2011-10-08
Products: 3
Vendors:
novell
CVE-2011-0334
10.0 HIGH

Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file.

Published: 2011-10-08
Products: 3
Vendors:
novell
CVE-2011-1696
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0,...

Published: 2011-10-08
Products: 10
Vendors:
novell
CVE-2011-2218
5.0 MEDIUM

Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vul...

Published: 2011-10-08
Products: 3
Vendors:
novell
CVE-2011-2219
5.0 MEDIUM

Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vul...

Published: 2011-10-08
Products: 3
Vendors:
novell
CVE-2011-2227
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0,...

Published: 2011-10-08
Products: 10
Vendors:
novell
CVE-2011-2661
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Directory.Item.name or (2)...

Published: 2011-10-08
Products: 3
Vendors:
novell
CVE-2011-2662
10.0 HIGH

Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a negative BYWEEKNO property in a weekly RRULE vari...

Published: 2011-10-08
Products: 3
Vendors:
novell