Vulnerabilities > Novell

DATE CVE VULNERABILITY TITLE RISK
2014-08-29 CVE-2014-0600 Information Exposure vulnerability in Novell Groupwise 2014
FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.
network
low complexity
novell CWE-200
7.8
2014-08-17 CVE-2014-0609 Security vulnerability in Novell Open Enterprise Server 11.0
Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintenance Update 9413 for Linux has unknown impact and attack vectors.
network
low complexity
novell
critical
10.0
2014-06-18 CVE-2014-0599 Cross-Site Scripting vulnerability in Novell Open Enterprise Server 11.0
Cross-site scripting (XSS) vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
novell CWE-79
4.3
2014-06-18 CVE-2014-0598 Path Traversal vulnerability in Novell Open Enterprise Server 11.0
Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified impact and remote attack vectors.
network
low complexity
novell CWE-22
critical
10.0
2014-05-08 CVE-2014-0595 Buffer Errors vulnerability in Novell Open Enterprise Server 11.0
/opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic circumstances by leveraging the granting of the F permission by an administrator.
local
high complexity
novell CWE-119
2.6
2014-04-16 CVE-2011-0993 Permissions, Privileges, and Access Controls vulnerability in Novell Suse Lifecycle Management Server 1.0
SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
novell CWE-264
2.1
2014-04-04 CVE-2014-0592 Permissions, Privileges, and Access Controls vulnerability in multiple products
Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass security group restrictions via unspecified vectors, related to floating IPs.
network
low complexity
crowbar novell CWE-264
7.5
2014-03-19 CVE-2014-1505 Information Exposure vulnerability in multiple products
The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing attack involving feDisplacementMap elements, a related issue to CVE-2013-1693.
7.5
2014-03-06 CVE-2013-3706 Path Traversal vulnerability in Novell Zenworks Configuration Management 11.2
Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a ..
network
low complexity
novell CWE-22
5.0
2013-12-28 CVE-2013-1096 Cross-Site Scripting vulnerability in Novell Identity Manager Roles Based Provisioning Module 4.0.2
Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId.
network
novell CWE-79
4.3