Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)5.6%—Novell Groupwise5/9/201417/6/2026
The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
ModificadaAlta (7.8)3.1%—Novell Groupwise29/8/201417/6/2026
FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.
ModificadaAlta (10)2.2%—Novell Open Enterprise Server17/8/201417/6/2026
Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintenance Update 9413 for Linux has unknown impact and attack vectors.
ModificadaMedia (4.3)2.0%—Novell Open Enterprise Server18/6/201417/6/2026
Cross-site scripting (XSS) vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)2.5%—Novell Open Enterprise Server18/6/201417/6/2026
Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified impact and remote attack vectors.
ModificadaBaja (2.6)0.34%—Novell Open Enterprise Server8/5/201417/6/2026
/opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic circumstances by leveraging the granting of the F permission by an administrator.
ModificadaBaja (2.1)0.37%—Novell Suse Lifecycle Management Server16/4/201416/6/2026
SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.
ModificadaAlta (7.5)1.6%—Crowbar BarclampNovell Suse Cloud4/4/201417/6/2026
Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass security group restrictions via unspecified vectors, related to floating IPs.
ModificadaAlta (7.5)4.0%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+1219/3/201417/6/2026
The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing…
ModificadaMedia (5)7.6%—Novell Zenworks Configuration Management6/3/201416/6/2026
Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595.
ModificadaMedia (4.3)2.0%—Novell Identity Manager Roles Based Provisioning Module28/12/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId.
ModificadaAlta (7.2)0.48%—Novell Suse Lifecycle Management ServerSuse Studio OnsiteSuse Webyast23/12/201316/6/2026
WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.
ModificadaMedia (4.9)0.34%—Novell Client22/12/201316/6/2026
The VBA32 AntiRootKit component for Novell Client 2 SP3 before IR5 on Windows allows local users to cause a denial of service (bugcheck and BSOD) via an IOCTL call for an invalid IOCTL.
ModificadaMedia (4.6)0.34%—Novell Suse Lifecycle Management Server10/12/201317/6/2026
SUSE Lifecycle Management Server (SLMS) before 1.3.7 uses world-readable permissions for the secret keys, which allows local users to gain privileges via unspecified vectors.
ModificadaMedia (4.3)1.3%—Novell Suse Lifecycle Management Server10/12/201316/6/2026
SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of this key from a product installation elsewhere.
ModificadaAlta (10)1.7%—Novell Suse Cloud2/12/201316/6/2026
The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecified impact and attack vectors.
ModificadaAlta (7.2)0.30%—Novell Suse Linux Enterprise FOR SAP Applications2/12/201316/6/2026
Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an unspecified impact via vectors related to a tmp/ directory.
ModificadaMedia (4.3)2.0%—Novell Suse Manager2/12/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Spacewalk service in SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11 SP1 allows remote attackers to inject arbitrary web script or HTML via an image name.
ModificadaMedia (4.3)1.6%—Novell Open Enterprise Server1/12/201316/6/2026
The HTTPSTK service in the novell-nrm package before 2.0.2-297.305.302.3 in Novell Open Enterprise Server 2 (OES 2) Linux, and OES 11 Linux Gold and SP1, does not make the intended SSL_free and SSL_shutdown calls for the close of a TCP connection, which allows remote attackers to cause a denial of service (service…
ModificadaMedia (5)1.3%—Novell Iprint1/12/201316/6/2026
The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to cause a denial of service via unspecified vectors.
ModificadaMedia (4.3)2.3%—Novell Suse Linux Enterprise Software Development KITNovell Suse Studio OnsiteNovell Suse Linux Enterprise DebuginfoGraphicsmagick+123/11/201316/6/2026
The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.
ModificadaMedia (6.8)0.75%—LibguestfsSuse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Server5/11/201316/6/2026
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by…
ModificadaMedia (6.8)1.2%—Novell Zenworks Configuration Management2/11/201317/6/2026
Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors.
ModificadaMedia (6.8)0.58%—Novell Zenworks Configuration Management2/11/201317/6/2026
Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaAlta (10)1.5%—Novell Zenworks Configuration Management2/11/201317/6/2026
Unspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors related to an "Application Exception."
Orbitaley — Vulnerabilidades