Search: "novell"

464 CVEs found

Novell eDirectory (eDir) 8.6.2 and Netware 5.1 eDir 85.x allows users with expired passwords to gain inappropriate permissions when logging in from Remote Manager.

Published: 2003-03-31
Products: 4
Vendors:
novell

RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection.

Published: 2003-04-11
Products: 1
Vendors:
novell
CVE-2002-1417
5.0 MEDIUM

Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL ...

Published: 2003-04-11
Products: 4
Vendors:
novell
CVE-2002-1418
5.0 MEDIUM

Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to cause a denial of service (AB...

Published: 2003-04-11
Products: 4
Vendors:
novell

The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.

Published: 2003-04-11
Products: 4
Vendors:
novell
CVE-2002-1437
5.0 MEDIUM

Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-enco...

Published: 2003-04-11
Products: 4
Vendors:
novell
CVE-2002-1438
5.0 MEDIUM

The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option.

Published: 2003-04-11
Products: 4
Vendors:
novell
CVE-2003-0562
5.0 MEDIUM

Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.

Published: 2003-08-27
Products: 6
Vendors:
novell
CVE-2003-0635
5.0 MEDIUM

Unknown vulnerability or vulnerabilities in Novell iChain 2.2 before Support Pack 1, with unknown impact, possibly related to unauthorized access to (1) NCPIP.NLM and (2) JSTCP.NLM.

Published: 2003-08-27
Products: 1
Vendors:
novell

Novell iChain 2.2 before Support Pack 1 does not properly verify that URL redirects match the DNS name of an accelerator, which allows attackers to redirect URLs to malicious web sites.

Published: 2003-08-27
Products: 1
Vendors:
novell
CVE-2003-0637
5.0 MEDIUM

Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess usernames and conduct brute force password...

Published: 2003-08-27
Products: 1
Vendors:
novell

Multiple buffer overflows in Novell iChain 2.1 before Field Patch 3, and iChain 2.2 before Field Patch 1a, allow attackers to cause a denial of service (ABEND) and possibly execute arbitrary code via ...

Published: 2003-08-27
Products: 3
Vendors:
novell
CVE-2003-0639
5.0 MEDIUM

Unknown vulnerability in Novell iChain 2.2 before Support Pack 1 allows users to access restricted or secure pages without authentication.

Published: 2003-08-27
Products: 3
Vendors:
novell

Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute a...

Published: 2003-10-27
Products: 4
Vendors:
novell

NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount file systems when XNFS ...

Published: 2003-12-15
Products: 2
Vendors:
novell
CVE-2003-1551
10.0 HIGH

Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."

Published: 2003-12-31
Products: 1
Vendors:
novell
CVE-2005-1247
5.0 MEDIUM

webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an expl...

Published: 2004-01-15
Products: 1
Vendors:
novell
CVE-2004-1457
5.0 MEDIUM

The Virtual Private Network (VPN) capability in Novell Bordermanager 3.8 allows remote attackers to cause a denial of service (ABEND in IKE.NLM) via a malformed IKE packet, as sent by the Striker ISAK...

Published: 2004-12-31
Products: 1
Vendors:
novell

Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS users with NDS, allows remote attackers to...

Published: 2004-12-31
Products: 10
Vendors:
cisco
CVE-2004-2103
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for ...

Published: 2004-12-31
Products: 2
Vendors:
novell