Vulnerabilities > Novell > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-04-24 CVE-2013-1088 Cross-Site Request Forgery (CSRF) vulnerability in Novell Imanager
Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
network
novell CWE-352
6.8
2013-04-19 CVE-2013-1086 Cross-Site Scripting vulnerability in Novell Groupwise
Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError attribute.
network
novell CWE-79
4.3
2013-04-07 CVE-2013-2770 Improper Input Validation vulnerability in Novell Kanaka 2.7/2.7.1
The installation functionality in the Novell Kanaka component before 2.8 for Novell Open Enterprise Server (OES) on Mac OS X does not verify the server's X.509 certificate during an SSL session, which allows man-in-the-middle attackers to spoof servers via an arbitrary certificate.
network
novell CWE-20
5.8
2013-03-29 CVE-2013-1079 Path Traversal vulnerability in Novell Zenworks Configuration Management
Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers to execute arbitrary local DLL files via a crafted web page that also calls the Initialize method.
network
novell CWE-22
6.8
2013-03-29 CVE-2012-6534 Permissions, Privileges, and Access Controls vulnerability in Novell Sentinel LOG Manager
Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results "Save Query As" "Save As Retention Policy" action.
network
novell CWE-264
4.3
2012-09-28 CVE-2012-4912 Cross-Site Scripting vulnerability in Novell Groupwise
Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to inject arbitrary web script or HTML via a crafted signature in an HTML e-mail message.
network
novell CWE-79
4.3
2012-09-28 CVE-2012-0419 Path Traversal vulnerability in Novell Groupwise
Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrary files via directory traversal sequences in a request.
network
low complexity
novell CWE-22
5.0
2012-09-19 CVE-2012-0272 Cross-Site Scripting vulnerability in Novell Groupwise 8.0/8.00
Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to inject arbitrary web script or HTML via the merge parameter.
network
novell CWE-79
4.3
2012-09-19 CVE-2011-3827 Buffer Errors vulnerability in Novell Groupwise 7.03/8.0/8.00
The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted date-time string in a .ics attachment.
network
novell CWE-119
4.3
2012-07-26 CVE-2011-3174 Buffer Errors vulnerability in Novell Zenworks Configuration Management 10.2/10.3/11
Buffer overflow in the DoFindReplace function in the ISGrid.Grid2.1 ActiveX control in InstallShield/ISGrid2.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary code via a long bstrReplaceText parameter.
network
novell CWE-119
6.8