Vulnerabilities > Novell

DATE CVE VULNERABILITY TITLE RISK
2011-10-08 CVE-2011-2219 Unspecified vulnerability in Novell Groupwise 8.0
Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2218.
network
low complexity
novell
5.0
2011-10-08 CVE-2011-2218 Unspecified vulnerability in Novell Groupwise 8.0
Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2219.
network
low complexity
novell
5.0
2011-10-08 CVE-2011-1696 Cross-Site Scripting vulnerability in Novell products
Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 692972.
network
novell CWE-79
4.3
2011-10-08 CVE-2011-0334 Buffer Errors vulnerability in Novell Groupwise 8.0
Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file.
network
low complexity
novell CWE-119
critical
10.0
2011-10-08 CVE-2011-0333 Buffer Errors vulnerability in Novell Groupwise 8.0
Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted TZNAME variable in a VCALENDAR attachment in an e-mail message, related to an "integer truncation error."
network
low complexity
novell CWE-119
critical
10.0
2011-09-06 CVE-2011-2654 Improper Input Validation vulnerability in Novell Cloud Manager 1.1.2
The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect privileges associated with a partially initialized session.
network
novell CWE-20
critical
9.3
2011-08-23 CVE-2011-2652 Cross-Site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted archive file list that is used in an overlay file.
4.3
2011-08-23 CVE-2011-2651 Unspecified vulnerability in the file browser in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename.
network
low complexity
marcus-schafer novell
7.5
2011-08-23 CVE-2011-2650 Cross-Site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RPM info display.
4.3
2011-08-23 CVE-2011-2649 Improper Input Validation vulnerability in multiple products
Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.
network
low complexity
marcus-schafer novell CWE-20
7.5