Vulnerability index

Browse CVEs

373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2012-6345 Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information. Zenworks Configuration Management 11.2.4+ Fix from $1,9502020-01-25 MEDIUM 6.1 CVE-2012-6344 Novell ZENworks Configuration Management before 11.2.4 allows XSS. Zenworks Configuration Management 11.2.4+ Fix from $1,6002020-01-25 HIGH 7.5 CVE-2017-9267 In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL B… Edirectory 9.0.3.1+ Fix from $1,9502018-03-02 HIGH 7.5 CVE-2017-9277 The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA. Edirectory after 9.0 Fix from $1,9502018-03-02 HIGH 7.8 CVE-2016-5759 The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root. Suse Linux Enterprise Desktop Mitigation only Fix from $1,9502017-09-08 CRITICAL 9.8 CVE-2015-0780EPSS 8% SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remo… Zenworks Configuration Management Mitigation only Fix from $2,3002017-08-09 CRITICAL 9.8 CVE-2015-0781 Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers … Zenworks Configuration Management Mitigation only Fix from $2,3002017-08-09 CRITICAL 9.8 CVE-2015-0782EPSS 7% SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attacke… Zenworks Configuration Management Mitigation only Fix from $2,3002017-08-09 CRITICAL 9.8 CVE-2015-0786EPSS 24% Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remot… Zenworks Configuration Management Mitigation only Fix from $2,3002017-08-09 HIGH 7.5 CVE-2015-0784EPSS 7% Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLo… Zenworks Configuration Management Mitigation only Fix from $1,9502017-08-09 HIGH 7.5 CVE-2015-0785EPSS 7% com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary… Zenworks Configuration Management Mitigation only Fix from $1,9502017-08-09 MEDIUM 6.5 CVE-2015-0783 The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename var… Zenworks Configuration Management Mitigation only Fix from $1,6002017-08-09 CRITICAL 9.8 CVE-2017-7432 Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability. Imanager Mitigation only Fix from $2,3002017-05-03 HIGH 8.8 CVE-2017-7431 Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management. Imanager Mitigation only Fix from $1,9502017-05-03 MEDIUM 6.1 CVE-2017-7430 Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework. Imanager Mitigation only Fix from $1,6002017-05-03 CRITICAL 9.8 CVE-2016-5762EPSS 6% Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbit… Groupwise after 2012 Fix from $2,3002017-04-20 MEDIUM 6.1 CVE-2016-5760 Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow … Groupwise after 2012 Fix from $1,6002017-04-20 MEDIUM 6.1 CVE-2016-5761 Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary we… Groupwise after 2012 Fix from $1,6002017-04-20 HIGH 7.5 CVE-2016-5747 A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to byp… Edirectory after 9.0 Fix from $1,9502017-03-23 HIGH 7.5 CVE-2016-9167 NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege … Edirectory after 9.0.1 Fix from $1,9502017-03-23 MEDIUM 6.5 CVE-2016-1603 An information leak in the NetIQ IDM ServiceNow Driver before 1.0.0.1 could expose cryptographic attributes to logged-in users. Netiq Idm Servicenow Driver after 1.0.0 Fix from $1,6002017-03-23 MEDIUM 6.5 CVE-2016-9168 A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjack… Edirectory after 9.0.1 Fix from $1,6002017-03-23 MEDIUM 6.1 CVE-2016-9169 A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 th… Groupwise Mitigation only Fix from $1,6002017-03-23 HIGH 8.8 CVE-2010-4314 Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overf… Iprint after 5.40 Fix from $1,9502017-03-11 HIGH 7.5 CVE-2017-5182 Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that … Open Enterprise Server Mitigation only Fix from $1,9502017-01-23 CRITICAL 9.1 CVE-2016-5763 Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10… Open Enterprise Server 11 Mitigation only Fix from $2,3002016-11-15 MEDIUM 5.4 CVE-2016-1598 XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role As… Identity Manager after 4.5.3 Fix from $1,6002016-10-27 HIGH 7.5 CVE-2015-8918 The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a … Suse Linux Enterprise Software Development Kit after 3.1.901a Fix from $1,9502016-09-20 HIGH 7.8 CVE-2016-1611 Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.sh, which allows local users … Filr after 2.0 Fix from $1,9502016-08-01 HIGH 7.5 CVE-2016-1610EPSS 12% Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows r… Filr after 2.0 Fix from $1,9502016-08-01