Vulnerability index

Browse CVEs

373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Edirectory HIGH 7.8
CVE-2006-4520

ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before 8.8.1 FTF2, does not properly handle NCP fragments with a negative length, which allows r…

Fix: after 8.7.3.8
Fix from $1,950 2007-04-30
Groupwise HIGH 10.0
CVE-2007-2171EPSS 24%

Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to…

Patch available
Fix from $1,950 2007-04-24
Netmail MEDIUM 6.8
CVE-2007-1350EPSS 19%

Stack-based buffer overflow in webadmin.exe in Novell NetMail 3.5.2 allows remote attackers to execute arbitrary code via a long username during HTTP…

Patch available
Fix from $1,600 2007-03-08
Bordermanager HIGH 7.5
CVE-2006-7155

Novell BorderManager 3.8 SP4 generates the same ISAKMP cookies for the same source IP and port number during the same day, which allows remote attack…

Patch available
Fix from $1,950 2007-03-07
Access Manager HIGH 9.0
CVE-2007-1309

Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, …

Patch available
Fix from $1,950 2007-03-07
Zenworks MEDIUM 6.4
CVE-2007-1119

Unspecified vulnerability in Novell ZENworks 7 Desktop Management Support Pack 1 before Hot patch 3 (ZDM7SP1HP3) allows remote attackers to upload im…

Patch available
Fix from $1,600 2007-02-27
Access Manager Identity Server MEDIUM 6.8
CVE-2007-0110

Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to injec…

Fix: after 3
Fix from $1,600 2007-01-09
Client MEDIUM 6.0
CVE-2007-0108

nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows…

Mitigation only
Fix from $1,600 2007-01-09
Netmail MEDIUM 6.5
CVE-2006-6761EPSS 53%

Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary cod…

Patch available
Fix from $1,600 2006-12-27
Netmail HIGH 9.0
CVE-2006-6424EPSS 59%

Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain I…

Fix: after 3.5.2
Fix from $1,950 2006-12-27
Netmail HIGH 9.0
CVE-2006-6425EPSS 58%

Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary cod…

Fix: after 3.5.2
Fix from $1,950 2006-12-27
Apache Http Server MEDIUM 6.8
CVE-2006-6675

Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to in…

No fix yet
Fix from $1,600 2006-12-21
Zenworks Patch Management Server HIGH 7.5
CVE-2006-6450EPSS 22%

Multiple SQL injection vulnerabilities in dagent/downloadreport.asp in Novell ZENworks Patch Management (ZPM) before 6.3.2.700 allow remote attackers…

Mitigation only
Fix from $1,950 2006-12-10
Client HIGH 10.0
CVE-2006-6443

Buffer overflow in the Novell Distributed Print Services (NDPS) Print Provider for Windows component (NDPPNT.DLL) in Novell Client 4.91 has unknown i…

No fix yet
Fix from $1,950 2006-12-10
Zenworks Asset Management HIGH 10.0
CVE-2006-6299EPSS 10%

Integer overflow in Msg.dll in Novell ZENworks 7 Asset Management (ZAM) before SP1 IR11 and the Collection client allows remote attackers to execute …

Patch available
Fix from $1,950 2006-12-05
Client MEDIUM 5.0
CVE-2006-6307

srvloc.sys in Novell Client for Windows before 4.91 SP3 allows remote attackers to cause an unspecified denial of service via a crafted packet to por…

Patch available
Fix from $1,600 2006-12-05
Netware Client HIGH 7.5
CVE-2006-5854EPSS 57%

Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbit…

Patch available
Fix from $1,950 2006-12-03
Edirectory HIGH 7.5
CVE-2006-5814

Unspecified vulnerability in Novell eDirectory allows remote attackers to execute arbitrary code, as demonstrated by vd_novell.pm, a "Novell eDirecto…

No fix yet
Fix from $1,950 2006-11-08
Edirectory MEDIUM 5.0
CVE-2006-5813

Unspecified vulnerability in Novell eDirectory 8.8 allows attackers to cause a denial of service, as demonstrated by vd_novell3.pm, a "Novell eDirect…

No fix yet
Fix from $1,600 2006-11-08
Edirectory MEDIUM 5.0
CVE-2006-4521

The BerDecodeLoginDataRequest function in the libnmasldap.so NMAS module in Novell eDirectory 8.8 and 8.8.1 before the Security Services 2.0.3 patch …

Patch available
Fix from $1,600 2006-11-04
Imanager HIGH 7.8
CVE-2006-4517

Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP …

Fix: after 2.5
Fix from $1,950 2006-11-01
Edirectory HIGH 7.5
CVE-2006-4177

Heap-based buffer overflow in the NCP engine in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted N…

Fix: after 8.8.1
Fix from $1,950 2006-10-24
Edirectory HIGH 7.5
CVE-2006-5478EPSS 84%

Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allo…

Patch available
Fix from $1,950 2006-10-24
Edirectory MEDIUM 5.0
CVE-2006-5479

The NCP Engine in Novell eDirectory before 8.7.3.8 FTF1 allows remote attackers to cause an unspecified denial of service via a certain "NCP Fragment…

Fix: after 8.7.3.8
Fix from $1,600 2006-10-24
Edirectory HIGH 10.0
CVE-2006-4509EPSS 7%

Integer overflow in the evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers t…

Patch available
Fix from $1,950 2006-10-24
Edirectory HIGH 10.0
CVE-2006-4510EPSS 7%

The evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary …

Patch available
Fix from $1,950 2006-10-24
Bordermanager MEDIUM 5.0
CVE-2006-5286

Unspecified vulnerability in IKE.NLM in Novell BorderManager 3.8 allows attackers to cause a denial of service (crash) via unknown attack vectors rel…

Patch available
Fix from $1,600 2006-10-13
Groupwise Messenger MEDIUM 5.0
CVE-2006-4511

Messenger Agents (nmma.exe) in Novell GroupWise 2.0.2 and 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted HTTP POST …

Patch available
Fix from $1,600 2006-10-05
Groupwise MEDIUM 5.0
CVE-2006-3268

Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow users to obtain "random programmatic access" to oth…

Patch available
Fix from $1,600 2006-06-29
Edirectory HIGH 10.0
CVE-2006-2496EPSS 9%

Buffer overflow in iMonitor 2.4 in Novell eDirectory 8.8 allows remote attackers to cause a denial of service (application crash) and possibly execut…

Patch available
Fix from $1,950 2006-05-20