Vulnerability index

Browse CVEs

145 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Suse Linux Enterprise Desktop HIGH 7.8
CVE-2016-5759

The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.

Mitigation only
Fix from $1,950 2017-09-08
Zenworks Configuration Management CRITICAL 9.8
CVE-2015-0780EPSS 8%

SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remo…

Mitigation only
Fix from $2,300 2017-08-09
Zenworks Configuration Management CRITICAL 9.8
CVE-2015-0781

Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers …

Mitigation only
Fix from $2,300 2017-08-09
Zenworks Configuration Management CRITICAL 9.8
CVE-2015-0782EPSS 7%

SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attacke…

Mitigation only
Fix from $2,300 2017-08-09
Zenworks Configuration Management CRITICAL 9.8
CVE-2015-0786EPSS 24%

Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remot…

Mitigation only
Fix from $2,300 2017-08-09
Zenworks Configuration Management HIGH 7.5
CVE-2015-0784EPSS 7%

Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLo…

Mitigation only
Fix from $1,950 2017-08-09
Zenworks Configuration Management HIGH 7.5
CVE-2015-0785EPSS 7%

com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary…

Mitigation only
Fix from $1,950 2017-08-09
Zenworks Configuration Management MEDIUM 6.5
CVE-2015-0783

The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename var…

Mitigation only
Fix from $1,600 2017-08-09
Imanager CRITICAL 9.8
CVE-2017-7432

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.

Mitigation only
Fix from $2,300 2017-05-03
Imanager HIGH 8.8
CVE-2017-7431

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.

Mitigation only
Fix from $1,950 2017-05-03
Imanager MEDIUM 6.1
CVE-2017-7430

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.

Mitigation only
Fix from $1,600 2017-05-03
Groupwise MEDIUM 6.1
CVE-2016-9169

A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 th…

Mitigation only
Fix from $1,600 2017-03-23
Open Enterprise Server HIGH 7.5
CVE-2017-5182

Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that …

Mitigation only
Fix from $1,950 2017-01-23
Open Enterprise Server 11 CRITICAL 9.1
CVE-2016-5763

Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10…

Mitigation only
Fix from $2,300 2016-11-15
Zenworks Configuration Management MEDIUM 5.3
CVE-2015-5970

The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection atta…

Mitigation only
Fix from $1,600 2016-02-18
Groupwise HIGH 7.8
CVE-2014-0600

FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via t…

Mitigation only
Fix from $1,950 2014-08-29
Open Enterprise Server HIGH 10.0
CVE-2014-0609

Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintena…

No fix yet
Fix from $1,950 2014-08-17
Open Enterprise Server HIGH 10.0
CVE-2014-0598

Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified imp…

Mitigation only
Fix from $1,950 2014-06-18
Suse Lifecycle Management Server HIGH 7.2
CVE-2013-3709

WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret to…

No fix yet
Fix from $1,950 2013-12-23
Suse Cloud HIGH 10.0
CVE-2012-0434

The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecified impact and attack vectors.

Mitigation only
Fix from $1,950 2013-12-02
Suse Linux Enterprise For Sap Applications HIGH 7.2
CVE-2012-0426

Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an un…

Mitigation only
Fix from $1,950 2013-12-02
Zenworks Configuration Management MEDIUM 5.0
CVE-2013-1084EPSS 6%

Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote …

Mitigation only
Fix from $1,600 2013-11-02
Client HIGH 7.2
CVE-2013-3697

Integer overflow in the NWFS.SYS kernel driver 4.91.5.8 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003 and the NCPL.SYS kernel drive…

No fix yet
Fix from $1,950 2013-07-31
Client HIGH 7.2
CVE-2013-3956EPSS 8%

The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows…

No fix yet
Fix from $1,950 2013-07-31
Zenworks Configuration Management MEDIUM 5.8
CVE-2013-1093

Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.…

Mitigation only
Fix from $1,600 2013-06-17
Zenworks Desktop Management HIGH 7.2
CVE-2013-1092

Multiple unquoted Windows search path vulnerabilities in Novell ZENworks Desktop Management (ZDM) 7 through 7.1 might allow local users to gain privi…

Mitigation only
Fix from $1,950 2013-05-05
Zenworks Configuration Management HIGH 10.0
CVE-2013-1080EPSS 77%

The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/js…

Mitigation only
Fix from $1,950 2013-03-29
Identity Manager Roles Based Provisioning Module HIGH 10.0
CVE-2013-1083

Unspecified vulnerability in the login functionality in the Reporting Module in Novell Identity Manager (aka IDM) Roles Based Provisioning Module 4.0…

Mitigation only
Fix from $1,950 2013-03-29
Zenworks Configuration Management MEDIUM 6.8
CVE-2013-1079

Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks C…

Mitigation only
Fix from $1,600 2013-03-29
Zenworks Mobile Management HIGH 7.5
CVE-2013-1081EPSS 68%

Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote attackers to include and execut…

Mitigation only
Fix from $1,950 2013-03-11