Vulnerability index

Browse CVEs

373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zenworks Configuration Management HIGH 7.5
CVE-2012-6345

Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.

Fix: 11.2.4+
Fix from $1,950 2020-01-25
Zenworks Configuration Management MEDIUM 6.1
CVE-2012-6344

Novell ZENworks Configuration Management before 11.2.4 allows XSS.

Fix: 11.2.4+
Fix from $1,600 2020-01-25
Edirectory HIGH 7.5
CVE-2017-9267

In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL B…

Fix: 9.0.3.1+
Fix from $1,950 2018-03-02
Edirectory HIGH 7.5
CVE-2017-9277

The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.

Fix: after 9.0
Fix from $1,950 2018-03-02
Suse Linux Enterprise Desktop HIGH 7.8
CVE-2016-5759

The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.

Mitigation only
Fix from $1,950 2017-09-08
Zenworks Configuration Management CRITICAL 9.8
CVE-2015-0780EPSS 8%

SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remo…

Mitigation only
Fix from $2,300 2017-08-09
Zenworks Configuration Management CRITICAL 9.8
CVE-2015-0781

Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers …

Mitigation only
Fix from $2,300 2017-08-09
Zenworks Configuration Management CRITICAL 9.8
CVE-2015-0782EPSS 7%

SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attacke…

Mitigation only
Fix from $2,300 2017-08-09
Zenworks Configuration Management CRITICAL 9.8
CVE-2015-0786EPSS 24%

Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remot…

Mitigation only
Fix from $2,300 2017-08-09
Zenworks Configuration Management HIGH 7.5
CVE-2015-0784EPSS 7%

Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLo…

Mitigation only
Fix from $1,950 2017-08-09
Zenworks Configuration Management HIGH 7.5
CVE-2015-0785EPSS 7%

com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary…

Mitigation only
Fix from $1,950 2017-08-09
Zenworks Configuration Management MEDIUM 6.5
CVE-2015-0783

The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename var…

Mitigation only
Fix from $1,600 2017-08-09
Imanager CRITICAL 9.8
CVE-2017-7432

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.

Mitigation only
Fix from $2,300 2017-05-03
Imanager HIGH 8.8
CVE-2017-7431

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.

Mitigation only
Fix from $1,950 2017-05-03
Imanager MEDIUM 6.1
CVE-2017-7430

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.

Mitigation only
Fix from $1,600 2017-05-03
Groupwise CRITICAL 9.8
CVE-2016-5762EPSS 6%

Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbit…

Fix: after 2012
Fix from $2,300 2017-04-20
Groupwise MEDIUM 6.1
CVE-2016-5760

Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow …

Fix: after 2012
Fix from $1,600 2017-04-20
Groupwise MEDIUM 6.1
CVE-2016-5761

Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary we…

Fix: after 2012
Fix from $1,600 2017-04-20
Edirectory HIGH 7.5
CVE-2016-5747

A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to byp…

Fix: after 9.0
Fix from $1,950 2017-03-23
Edirectory HIGH 7.5
CVE-2016-9167

NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege …

Fix: after 9.0.1
Fix from $1,950 2017-03-23
Netiq Idm Servicenow Driver MEDIUM 6.5
CVE-2016-1603

An information leak in the NetIQ IDM ServiceNow Driver before 1.0.0.1 could expose cryptographic attributes to logged-in users.

Fix: after 1.0.0
Fix from $1,600 2017-03-23
Edirectory MEDIUM 6.5
CVE-2016-9168

A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjack…

Fix: after 9.0.1
Fix from $1,600 2017-03-23
Groupwise MEDIUM 6.1
CVE-2016-9169

A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 th…

Mitigation only
Fix from $1,600 2017-03-23
Iprint HIGH 8.8
CVE-2010-4314

Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overf…

Fix: after 5.40
Fix from $1,950 2017-03-11
Open Enterprise Server HIGH 7.5
CVE-2017-5182

Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that …

Mitigation only
Fix from $1,950 2017-01-23
Open Enterprise Server 11 CRITICAL 9.1
CVE-2016-5763

Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10…

Mitigation only
Fix from $2,300 2016-11-15
Identity Manager MEDIUM 5.4
CVE-2016-1598

XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role As…

Fix: after 4.5.3
Fix from $1,600 2016-10-27
Suse Linux Enterprise Software Development Kit HIGH 7.5
CVE-2015-8918

The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a …

Fix: after 3.1.901a
Fix from $1,950 2016-09-20
Filr HIGH 7.8
CVE-2016-1611

Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.sh, which allows local users …

Fix: after 2.0
Fix from $1,950 2016-08-01
Filr HIGH 7.5
CVE-2016-1610EPSS 12%

Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows r…

Fix: after 2.0
Fix from $1,950 2016-08-01