Vulnerabilities > Novell

DATE CVE VULNERABILITY TITLE RISK
2011-08-09 CVE-2011-2223 Cryptographic Issues vulnerability in Novell Data Synchronizer and Mobility Pack
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
novell CWE-310
5.0
2011-08-09 CVE-2011-2222 Remote Security vulnerability in Novell Data Synchronizer Mobility Pack
Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors.
network
novell
4.3
2011-08-09 CVE-2011-2221 Permissions, Privileges, and Access Controls vulnerability in Novell Data Synchronizer and Mobility Pack
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and obtain sensitive GroupWise information via unspecified vectors.
network
low complexity
novell CWE-264
5.0
2011-07-17 CVE-2011-2750 Resource Management Errors vulnerability in Novell File Reporter 1.0.1/1.0.1.1/1.0.2
NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.
network
low complexity
novell CWE-399
5.0
2011-07-14 CVE-2011-2220 Buffer Errors vulnerability in Novell File Reporter and File Reporter Engine
Stack-based buffer overflow in NFREngine.exe in Novell File Reporter Engine before 1.0.2.53, as used in Novell File Reporter and other products, allows remote attackers to execute arbitrary code via a crafted RECORD element.
network
low complexity
novell CWE-119
critical
10.0
2011-06-09 CVE-2011-1708 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Iprint
Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs cookie.
network
novell CWE-119
critical
9.3
2011-06-09 CVE-2011-1707 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Iprint
Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs parameter in a printer-url.
network
novell CWE-119
critical
9.3
2011-06-09 CVE-2011-1706 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Iprint
Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted iprint-client-config-info parameter in a printer-url.
network
novell CWE-119
critical
9.3
2011-06-09 CVE-2011-1705 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Iprint
Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted client-file-name parameter in a printer-url.
network
novell CWE-119
critical
9.3
2011-06-09 CVE-2011-1704 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Iprint
Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted core-package parameter in a printer-url.
network
novell CWE-119
critical
9.3