Search: "novell"

464 CVEs found

CVE-2014-5213
4.0 MEDIUM

nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote authenticated users to obtain sensitive information from process memor...

Published: 2014-12-19
Products: 1
Vendors:
novell
CVE-2010-5323
10.0 HIGH

Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code...

Published: 2015-06-07
Products: 3
Vendors:
novell
CVE-2010-5324
10.0 HIGH

Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code...

Published: 2015-06-07
Products: 3
Vendors:
novell
CVE-2015-0779
10.0 HIGH

Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a crafted directory n...

Published: 2015-06-07
Products: 6
Vendors:
novell
CVE-2014-0611
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014 before Support Pack 2 allow remote attackers to inject arbitrary web script or ...

Published: 2015-07-22
Products: 2
Vendors:
novell
CVE-2015-5970
5.3 MEDIUM

The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed...

Published: 2016-02-18
Products: 5
Vendors:
novell
CVE-2015-5968
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Novell Filr 1.2 before Hot Patch 4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Published: 2016-03-18
Products: 1
Vendors:
novell

Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a ....

Published: 2016-04-22
Products: 1
Vendors:
novell
CVE-2016-1594
6.5 MEDIUM

Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a...

Published: 2016-04-22
Products: 1
Vendors:
novell
CVE-2016-1595
6.5 MEDIUM

LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection atta...

Published: 2016-04-22
Products: 1
Vendors:
novell
CVE-2016-1596
5.4 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (...

Published: 2016-04-22
Products: 1
Vendors:
novell

Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Security Update 2 allow remote attackers to hijack the authentication of administra...

Published: 2016-08-01
Products: 2
Vendors:
novell

vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ntpServer par...

Published: 2016-08-01
Products: 2
Vendors:
novell
CVE-2016-1609
5.4 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allow remote authenticated users to inject arbitrary web script or HTML...

Published: 2016-08-01
Products: 2
Vendors:
novell

Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote attackers to bypass intended access restricti...

Published: 2016-08-01
Products: 2
Vendors:
novell

Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.sh, which allows local users to gain privileges by replacing this file's content...

Published: 2016-08-01
Products: 2
Vendors:
novell
CVE-2016-5763
9.1 CRITICAL

Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10990, OES11 SP3 before Scheduled Maintenance Update ...

Published: 2016-11-15
Products: 4
Vendors:
novell

Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overflowing the "name" parameter.

Published: 2017-03-11
Products: 4
Vendors:
microsoft novell

A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging pred...

Published: 2017-03-23
Products: 1
Vendors:
novell

NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would ...

Published: 2017-03-23
Products: 1
Vendors:
novell