Search: "novell"

464 CVEs found

Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote attackers to include and execute arbitrary local files via the language parameter.

Published: 2013-03-11
Products: 2
Vendors:
novell
CVE-2012-6534
4.3 MEDIUM

Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote ...

Published: 2013-03-29
Products: 8
Vendors:
novell
CVE-2013-1079
6.8 MEDIUM

Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 all...

Published: 2013-03-29
Products: 8
Vendors:
novell
CVE-2013-1080
10.0 HIGH

The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to condu...

Published: 2013-03-29
Products: 2
Vendors:
novell

Directory traversal vulnerability in DUSAP.php in Novell ZENworks Mobile Management before 2.7.1 allows remote attackers to include and execute arbitrary local files via the language parameter.

Published: 2013-03-29
Products: 2
Vendors:
novell
CVE-2013-1083
10.0 HIGH

Unspecified vulnerability in the login functionality in the Reporting Module in Novell Identity Manager (aka IDM) Roles Based Provisioning Module 4.0.2 before Field Patch C has unknown impact and atta...

Published: 2013-03-29
Products: 1
Vendors:
novell

Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earlier, and Novell Messenger 2.1.x and 2.2.x before 2.2.2, allows remote attackers to execute arbitrary...

Published: 2013-03-29
Products: 7
Vendors:
novell
CVE-2013-2770
5.8 MEDIUM

The installation functionality in the Novell Kanaka component before 2.8 for Novell Open Enterprise Server (OES) on Mac OS X does not verify the server's X.509 certificate during an SSL session, which...

Published: 2013-04-07
Products: 3
Vendors:
novell
CVE-2013-1086
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote attackers to inject arbitrary web script or HTML via vectors involving an...

Published: 2013-04-19
Products: 50
Vendors:
novell
CVE-2013-1088
6.8 MEDIUM

Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validat...

Published: 2013-04-24
Products: 17
Vendors:
novell
CVE-2013-3268
10.0 HIGH

Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.

Published: 2013-04-24
Products: 17
Vendors:
novell
CVE-2013-1091
10.0 HIGH

Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute arbitrary code via unspecified vectors.

Published: 2013-05-02
Products: 27
Vendors:
novell

Multiple unquoted Windows search path vulnerabilities in Novell ZENworks Desktop Management (ZDM) 7 through 7.1 might allow local users to gain privileges via a Trojan horse "program" file in the C: f...

Published: 2013-05-05
Products: 2
Vendors:
novell
CVE-2013-1093
5.8 MEDIUM

Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote att...

Published: 2013-06-17
Products: 4
Vendors:
novell
CVE-2013-1094
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in a ZCC page in zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitra...

Published: 2013-06-17
Products: 4
Vendors:
novell
CVE-2013-1095
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary we...

Published: 2013-06-17
Products: 4
Vendors:
novell
CVE-2013-1097
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary we...

Published: 2013-06-17
Products: 4
Vendors:
novell
CVE-2013-1087
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in the client in Novell GroupWise through 8.0.3 HP3, and 2012 through SP2, on Windows allows user-assisted remote attackers to inject arbitrary web script or H...

Published: 2013-07-15
Products: 48
Vendors:
microsoft novell

Integer overflow in the NWFS.SYS kernel driver 4.91.5.8 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003 and the NCPL.SYS kernel driver in Novell Client 2 SP2 on Windows Vista and Windo...

Published: 2013-07-31
Products: 11
Vendors:
microsoft novell

The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows Server 2008; and Novell Client 2 SP3 on Windows Se...

Published: 2013-07-31
Products: 11
Vendors:
microsoft novell