Search: "novell"

464 CVEs found

CVE-2013-1084
5.0 MEDIUM

Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers to read arbitrary files via a .. (dot dot...

Published: 2013-11-02
Products: 1
Vendors:
novell
CVE-2013-6344
4.3 MEDIUM

The ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows attackers to conduct cross-frame scripting attacks via unknown vectors.

Published: 2013-11-02
Products: 9
Vendors:
novell
CVE-2013-6345
10.0 HIGH

Unspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors related to an "Application Exception."

Published: 2013-11-02
Products: 9
Vendors:
novell
CVE-2013-6346
6.8 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack the authentication of unspecified vict...

Published: 2013-11-02
Products: 9
Vendors:
novell
CVE-2013-6347
6.8 MEDIUM

Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors.

Published: 2013-11-02
Products: 9
Vendors:
novell
CVE-2013-3708
5.0 MEDIUM

The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to cause a denial of service via unspecified vectors.

Published: 2013-12-01
Products: 31
Vendors:
novell
CVE-2013-3707
4.3 MEDIUM

The HTTPSTK service in the novell-nrm package before 2.0.2-297.305.302.3 in Novell Open Enterprise Server 2 (OES 2) Linux, and OES 11 Linux Gold and SP1, does not make the intended SSL_free and SSL_sh...

Published: 2013-12-01
Products: 2
Vendors:
novell
CVE-2013-3705
4.9 MEDIUM

The VBA32 AntiRootKit component for Novell Client 2 SP3 before IR5 on Windows allows local users to cause a denial of service (bugcheck and BSOD) via an IOCTL call for an invalid IOCTL.

Published: 2013-12-22
Products: 1
Vendors:
novell
CVE-2013-1096
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script ...

Published: 2013-12-28
Products: 1
Vendors:
novell
CVE-2013-3706
5.0 MEDIUM

Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update p...

Published: 2014-03-06
Products: 1
Vendors:
novell

/opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permissio...

Published: 2014-05-08
Products: 1
Vendors:
novell
CVE-2014-0598
10.0 HIGH

Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified impact and remote attack vectors.

Published: 2014-06-18
Products: 1
Vendors:
novell
CVE-2014-0599
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux allows remote attackers to inject arbitrary web script or HTML ...

Published: 2014-06-18
Products: 1
Vendors:
novell
CVE-2014-4509
4.6 MEDIUM

The MKDQUOTESAFE function in the Fan-out driver scripts in Fan-Out Platform Services in Novell Identity Manager (aka IDM) 4.0.2 allows local users to execute arbitrary commands by leveraging eDirector...

Published: 2014-06-21
Products: 1
Vendors:
netiq
CVE-2014-0609
10.0 HIGH

Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintenance Update 9413 for Linux has unknown impact and at...

Published: 2014-08-17
Products: 2
Vendors:
novell

EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P07, when Novell Identity Manager (aka NovellIM) is used, allows remote attackers ...

Published: 2014-08-28
Products: 5
Vendors:
emc

FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-...

Published: 2014-08-29
Products: 1
Vendors:
novell
CVE-2014-0610
10.0 HIGH

The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer derefer...

Published: 2014-09-05
Products: 19
Vendors:
microsoft novell
CVE-2014-3696
5.0 MEDIUM

nmevent.c in the Novell GroupWise protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a crafted server message that trigger...

Published: 2014-10-29
Products: 10
Vendors:
pidgin
CVE-2014-5212
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote attackers to inject arbitrary web script or HTML via the rdn parameter...

Published: 2014-12-19
Products: 1
Vendors:
novell