Vulnerabilities > Novell > High

DATE CVE VULNERABILITY TITLE RISK
2011-11-30 CVE-2011-4191 Buffer Errors vulnerability in Novell Netware 6.5
Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (abend or NFS outage) via long packets.
network
low complexity
novell CWE-119
7.5
2011-11-30 CVE-2011-3173 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Iprint Open Enterprise Server 2
Stack-based buffer overflow in the GetDriverSettings function in nipplib.dll in the iPrint client in Novell Open Enterprise Server 2 (aka OES2) SP3 allows remote attackers to execute arbitrary code via a long (1) hostname or (2) port field.
network
low complexity
novell CWE-119
7.5
2011-08-23 CVE-2011-2651 Unspecified vulnerability in the file browser in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename.
network
low complexity
marcus-schafer novell
7.5
2011-08-23 CVE-2011-2649 Improper Input Validation vulnerability in multiple products
Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.
network
low complexity
marcus-schafer novell CWE-20
7.5
2011-08-23 CVE-2011-2648 Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a filter in a modified file.
network
low complexity
marcus-schafer novell
7.5
2011-08-23 CVE-2011-2647 Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted archive name in the list of testdrive modified files.
network
low complexity
marcus-schafer novell
7.5
2011-08-23 CVE-2011-2646 Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename in the list of testdrive modified files.
network
low complexity
marcus-schafer novell
7.5
2011-08-23 CVE-2011-2645 Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename for a custom RPM.
network
low complexity
marcus-schafer novell
7.5
2011-02-19 CVE-2010-4328 Buffer Errors vulnerability in Novell Iprint Open Enterprise Server 2
Multiple stack-based buffer overflows in opt/novell/iprint/bin/ipsmd in Novell iPrint for Linux Open Enterprise Server 2 SP2 and SP3 allow remote attackers to execute arbitrary code via unspecified LPR opcodes.
network
low complexity
novell CWE-119
7.5
2011-02-19 CVE-2010-4323 Buffer Errors vulnerability in Novell Zenworks Configuration Manager 10.3.1/10.3.2
Heap-based buffer overflow in novell-tftp.exe in Novell ZENworks Configuration Manager (ZCM) 10.3.1, 10.3.2, and 11.0, and earlier versions, allows remote attackers to execute arbitrary code via a long TFTP request.
network
low complexity
novell CWE-119
7.5