Vulnerability index

Browse CVEs

373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netware MEDIUM 5.0
CVE-2005-1060

Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Pa…

Patch available
Fix from $1,600 2005-05-02
Ichain HIGH 7.5
CVE-2005-0798

Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote att…

Mitigation only
Fix from $1,950 2005-03-15
Groupwise MEDIUM 5.0
CVE-2005-0296

NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated …

Mitigation only
Fix from $1,600 2005-01-17
Netware HIGH 10.0
CVE-2004-2734

webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volum…

Mitigation only
Fix from $1,950 2004-12-31
Ichain HIGH 7.5
CVE-2004-2314

The Telnet listener for Novell iChain Server before 2.2 Field Patch 3b 2.2.116 does not have a password by default, which allows remote attackers to …

Fix: after 2.2
Fix from $1,950 2004-12-31
Ichain HIGH 7.5
CVE-2004-2579

ACLCHECK module in Novell iChain 2.3 allows attackers to bypass access control rules of an unspecified component via an unspecified attack vector inv…

Patch available
Fix from $1,950 2004-12-31
Client Firewall HIGH 7.2
CVE-2004-2554

Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by op…

Mitigation only
Fix from $1,950 2004-12-31
Internet Messaging System MEDIUM 6.4
CVE-2004-2298

Novell Internet Messaging System (NIMS) 2.6 and 3.0, and NetMail 3.1 and 3.5, is installed with a default NMAP authentication credential, which allow…

Patch available
Fix from $1,600 2004-12-31
Ichain MEDIUM 5.8
CVE-2004-2580

Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via unspecified vectors.

Patch available
Fix from $1,600 2004-12-31
Bordermanager MEDIUM 5.0
CVE-2004-1457

The Virtual Private Network (VPN) capability in Novell Bordermanager 3.8 allows remote attackers to cause a denial of service (ABEND in IKE.NLM) via …

Patch available
Fix from $1,600 2004-12-31
Netware MEDIUM 5.0
CVE-2004-2104EPSS 12%

Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, v…

Mitigation only
Fix from $1,600 2004-12-31
Netware MEDIUM 5.0
CVE-2004-2105

The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt files via a full pathname in th…

Mitigation only
Fix from $1,600 2004-12-31
Netware MEDIUM 5.0
CVE-2004-2106

Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3)…

Mitigation only
Fix from $1,600 2004-12-31
Ichain MEDIUM 5.0
CVE-2004-2581

Novell iChain 2.3 allows attackers to cause a denial of service via a URL with a "specific string."

Patch available
Fix from $1,600 2004-12-31
Ichain MEDIUM 5.0
CVE-2004-2582

Novell iChain 2.3 includes the build number in the VIA line of the proxy server's HTTP headers, which allows remote attackers to obtain sensitive inf…

Patch available
Fix from $1,600 2004-12-31
Nsure Audit MEDIUM 5.0
CVE-2005-1247

webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certifica…

No fix yet
Fix from $1,600 2004-01-15
Groupwise HIGH 10.0
CVE-2003-1551

Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."

Fix: after 6.0_sp3
Fix from $1,950 2003-12-31
Netware HIGH 7.5
CVE-2003-0976

NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which…

Patch available
Fix from $1,950 2003-12-15
Zenworks Desktops HIGH 7.5
CVE-2003-1150

Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers …

Mitigation only
Fix from $1,950 2003-10-27
Ichain HIGH 7.5
CVE-2003-0636

Novell iChain 2.2 before Support Pack 1 does not properly verify that URL redirects match the DNS name of an accelerator, which allows attackers to r…

Patch available
Fix from $1,950 2003-08-27
Ichain HIGH 7.5
CVE-2003-0638

Multiple buffer overflows in Novell iChain 2.1 before Field Patch 3, and iChain 2.2 before Field Patch 1a, allow attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2003-08-27
Netware MEDIUM 5.0
CVE-2003-0562EPSS 14%

Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a lon…

Mitigation only
Fix from $1,600 2003-08-27
Ichain MEDIUM 5.0
CVE-2003-0635

Unknown vulnerability or vulnerabilities in Novell iChain 2.2 before Support Pack 1, with unknown impact, possibly related to unauthorized access to …

Mitigation only
Fix from $1,600 2003-08-27
Ichain MEDIUM 5.0
CVE-2003-0637

Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers …

Patch available
Fix from $1,600 2003-08-27
Ichain MEDIUM 5.0
CVE-2003-0639

Unknown vulnerability in Novell iChain 2.2 before Support Pack 1 allows users to access restricted or secure pages without authentication.

Mitigation only
Fix from $1,600 2003-08-27
Netware HIGH 7.5
CVE-2002-1413

RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL…

Patch available
Fix from $1,950 2003-04-11
Netware HIGH 7.5
CVE-2002-1436EPSS 7%

The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.

Patch available
Fix from $1,950 2003-04-11
Small Business Suite MEDIUM 5.0
CVE-2002-1417EPSS 17%

Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows …

Patch available
Fix from $1,600 2003-04-11
Small Business Suite MEDIUM 5.0
CVE-2002-1418

Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allow…

Patch available
Fix from $1,600 2003-04-11
Netware MEDIUM 5.0
CVE-2002-1437EPSS 17%

Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary fil…

Patch available
Fix from $1,600 2003-04-11