Vulnerabilities > Novell

DATE CVE VULNERABILITY TITLE RISK
2008-08-06 CVE-2008-3488 Permissions, Privileges, and Access Controls vulnerability in Novell Imanager
Unspecified vulnerability in Novell iManager before 2.7 SP1 (2.7.1) allows remote attackers to delete Plug-in Studio created Property Book Pages via unknown vectors.
network
low complexity
novell CWE-264
7.5
2008-07-14 CVE-2008-3159 Numeric Errors vulnerability in Novell Edirectory 8.7.3/8.8
Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ftf2 allows remote attackers to execute arbitrary code via unspecified vectors that trigger a stack-based buffer overflow, related to "flawed arithmetic."
network
low complexity
novell CWE-189
critical
10.0
2008-07-14 CVE-2008-1809 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Edirectory 8.7.3/8.8
Heap-based buffer overflow in Novell eDirectory 8.7.3 before 8.7.3.10b, and 8.8 before 8.8.2 FTF2, allows remote attackers to execute arbitrary code via an LDAP search request containing "NULL search parameters."
network
low complexity
novell CWE-119
critical
10.0
2008-07-11 CVE-2008-3158 Permissions, Privileges, and Access Controls vulnerability in Novell Client for Windows 4.91Sp4
Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory.
local
novell CWE-264
6.9
2008-07-09 CVE-2008-2931 Improper Privilege Management vulnerability in multiple products
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
local
low complexity
linux debian novell opensuse canonical CWE-269
7.8
2008-07-09 CVE-2008-2812 NULL Pointer Dereference vulnerability in multiple products
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.
7.8
2008-06-30 CVE-2008-2908 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Iprint Client
Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attackers to execute arbitrary code via a long value of the (1) operation, (2) printer-url, or (3) target-frame parameter.
network
novell CWE-119
critical
9.3
2008-06-18 CVE-2008-0925 Cross-Site Scripting vulnerability in Novell Edirectory
Cross-site scripting (XSS) vulnerability in the iMonitor interface in Novell eDirectory 8.7.3.x before 8.7.3 sp10, and 8.8.x before 8.8.2 ftf2, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters that are used within "error messages of the HTTP stack."
network
novell CWE-79
4.3
2008-06-13 CVE-2008-2704 Improper Input Validation vulnerability in Novell Groupwise Messenger
Novell GroupWise Messenger (GWIM) before 2.0.3 Hot Patch 1 allows remote attackers to cause a denial of service (crash) via a long user ID, possibly involving a popup alert.
network
low complexity
novell CWE-20
5.0
2008-06-13 CVE-2008-2703 Buffer Errors vulnerability in Novell Groupwise Messenger 2.0/2.0.2/2.0.3
Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow remote attackers to execute arbitrary code via "spoofed server responses" that contain a long string after the NM_A_SZ_TRANSACTION_ID field name.
network
low complexity
novell CWE-119
critical
10.0