Vulnerability index

Browse CVEs

373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filr MEDIUM 5.4
CVE-2016-1609

Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allow remote authent…

Fix: after 2.0
Fix from $1,600 2016-08-01
Filr HIGH 8.8
CVE-2016-1608EPSS 11%

vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary com…

Fix: after 2.0
Fix from $1,950 2016-08-01
Filr HIGH 7.2
CVE-2016-1607

Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Security Update 2 allow remote a…

Fix: after 2.0
Fix from $1,950 2016-08-01
Service Desk MEDIUM 5.4
CVE-2016-1596

Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrar…

Fix: after 7.1
Fix from $1,600 2016-04-22
Service Desk MEDIUM 6.5
CVE-2016-1595EPSS 7%

LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to co…

Fix: after 7.1
Fix from $1,600 2016-04-22
Service Desk MEDIUM 6.5
CVE-2016-1594EPSS 7%

Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as de…

Fix: after 7.1
Fix from $1,600 2016-04-22
Service Desk HIGH 7.2
CVE-2016-1593EPSS 64%

Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrator…

Fix: after 7.1
Fix from $1,950 2016-04-22
Filr MEDIUM 6.1
CVE-2015-5968

Cross-site scripting (XSS) vulnerability in Novell Filr 1.2 before Hot Patch 4 allows remote attackers to inject arbitrary web script or HTML via a c…

Fix: after 1.2
Fix from $1,600 2016-03-18
Zenworks Configuration Management MEDIUM 5.3
CVE-2015-5970

The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection atta…

Mitigation only
Fix from $1,600 2016-02-18
Zenworks Configuration Management HIGH 10.0
CVE-2015-0779EPSS 75%

Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers …

Patch available
Fix from $1,950 2015-06-07
Zenworks Configuration Management HIGH 10.0
CVE-2010-5324EPSS 72%

Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.…

Patch available
Fix from $1,950 2015-06-07
Zenworks Configuration Management HIGH 10.0
CVE-2010-5323EPSS 14%

Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.…

Patch available
Fix from $1,950 2015-06-07
Suse Linux Enterprise Desktop MEDIUM 6.9
CVE-2015-0403

Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows local users to affect confidentiality, integrity, and availability via unknow…

Patch available
Fix from $1,600 2015-01-21
Groupwise HIGH 10.0
CVE-2014-0610EPSS 6%

The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or…

Fix: after 8.03
Fix from $1,950 2014-09-05
Groupwise HIGH 7.8
CVE-2014-0600

FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via t…

Mitigation only
Fix from $1,950 2014-08-29
Open Enterprise Server HIGH 10.0
CVE-2014-0609

Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintena…

No fix yet
Fix from $1,950 2014-08-17
Open Enterprise Server HIGH 10.0
CVE-2014-0598

Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified imp…

Mitigation only
Fix from $1,950 2014-06-18
Zenworks Configuration Management MEDIUM 5.0
CVE-2013-3706EPSS 8%

Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbit…

Patch available
Fix from $1,600 2014-03-06
Suse Lifecycle Management Server HIGH 7.2
CVE-2013-3709

WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret to…

No fix yet
Fix from $1,950 2013-12-23
Suse Cloud HIGH 10.0
CVE-2012-0434

The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecified impact and attack vectors.

Mitigation only
Fix from $1,950 2013-12-02
Suse Linux Enterprise For Sap Applications HIGH 7.2
CVE-2012-0426

Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an un…

Mitigation only
Fix from $1,950 2013-12-02
Iprint MEDIUM 5.0
CVE-2013-3708

The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to cause a denial of service via unspecified vectors.

Fix: after 5.90
Fix from $1,600 2013-12-01
Zenworks Configuration Management MEDIUM 6.8
CVE-2013-6347

Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via uns…

Fix: after 11.2.3
Fix from $1,600 2013-11-02
Zenworks Configuration Management HIGH 10.0
CVE-2013-6345

Unspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors relat…

Fix: after 11.2.3
Fix from $1,950 2013-11-02
Zenworks Configuration Management MEDIUM 6.8
CVE-2013-6346

Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attacke…

Fix: after 11.2.3
Fix from $1,600 2013-11-02
Zenworks Configuration Management MEDIUM 5.0
CVE-2013-1084EPSS 6%

Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote …

Mitigation only
Fix from $1,600 2013-11-02
Client HIGH 7.2
CVE-2013-3697

Integer overflow in the NWFS.SYS kernel driver 4.91.5.8 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003 and the NCPL.SYS kernel drive…

No fix yet
Fix from $1,950 2013-07-31
Client HIGH 7.2
CVE-2013-3956EPSS 8%

The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows…

No fix yet
Fix from $1,950 2013-07-31
Zenworks Configuration Management MEDIUM 5.8
CVE-2013-1093

Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.…

Mitigation only
Fix from $1,600 2013-06-17
Zenworks Desktop Management HIGH 7.2
CVE-2013-1092

Multiple unquoted Windows search path vulnerabilities in Novell ZENworks Desktop Management (ZDM) 7 through 7.1 might allow local users to gain privi…

Mitigation only
Fix from $1,950 2013-05-05