Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 5.6% | — | Novell Groupwise | 5/9/2014 | 17/6/2026 | The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors. | |
| Modificada | Alta (7.8) | 3.1% | — | Novell Groupwise | 29/8/2014 | 17/6/2026 | FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287. | |
| Modificada | Alta (10) | 2.2% | — | Novell Open Enterprise Server | 17/8/2014 | 17/6/2026 | Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintenance Update 9413 for Linux has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Novell Open Enterprise Server | 18/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 2.5% | — | Novell Open Enterprise Server | 18/6/2014 | 17/6/2026 | Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified impact and remote attack vectors. | |
| Modificada | Baja (2.6) | 0.34% | — | Novell Open Enterprise Server | 8/5/2014 | 17/6/2026 | /opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic circumstances by leveraging the granting of the F permission by an administrator. | |
| Modificada | Baja (2.1) | 0.37% | — | Novell Suse Lifecycle Management Server | 16/4/2014 | 16/6/2026 | SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.6% | — | Crowbar BarclampNovell Suse Cloud | 4/4/2014 | 17/6/2026 | Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass security group restrictions via unspecified vectors, related to floating IPs. | |
| Modificada | Alta (7.5) | 4.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+12 | 19/3/2014 | 17/6/2026 | The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing… | |
| Modificada | Media (5) | 7.6% | — | Novell Zenworks Configuration Management | 6/3/2014 | 16/6/2026 | Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595. | |
| Modificada | Media (4.3) | 2.0% | — | Novell Identity Manager Roles Based Provisioning Module | 28/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId. | |
| Modificada | Alta (7.2) | 0.48% | — | Novell Suse Lifecycle Management ServerSuse Studio OnsiteSuse Webyast | 23/12/2013 | 16/6/2026 | WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file. | |
| Modificada | Media (4.9) | 0.34% | — | Novell Client | 22/12/2013 | 16/6/2026 | The VBA32 AntiRootKit component for Novell Client 2 SP3 before IR5 on Windows allows local users to cause a denial of service (bugcheck and BSOD) via an IOCTL call for an invalid IOCTL. | |
| Modificada | Media (4.6) | 0.34% | — | Novell Suse Lifecycle Management Server | 10/12/2013 | 17/6/2026 | SUSE Lifecycle Management Server (SLMS) before 1.3.7 uses world-readable permissions for the secret keys, which allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Novell Suse Lifecycle Management Server | 10/12/2013 | 16/6/2026 | SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of this key from a product installation elsewhere. | |
| Modificada | Alta (10) | 1.7% | — | Novell Suse Cloud | 2/12/2013 | 16/6/2026 | The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecified impact and attack vectors. | |
| Modificada | Alta (7.2) | 0.30% | — | Novell Suse Linux Enterprise FOR SAP Applications | 2/12/2013 | 16/6/2026 | Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an unspecified impact via vectors related to a tmp/ directory. | |
| Modificada | Media (4.3) | 2.0% | — | Novell Suse Manager | 2/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Spacewalk service in SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11 SP1 allows remote attackers to inject arbitrary web script or HTML via an image name. | |
| Modificada | Media (4.3) | 1.6% | — | Novell Open Enterprise Server | 1/12/2013 | 16/6/2026 | The HTTPSTK service in the novell-nrm package before 2.0.2-297.305.302.3 in Novell Open Enterprise Server 2 (OES 2) Linux, and OES 11 Linux Gold and SP1, does not make the intended SSL_free and SSL_shutdown calls for the close of a TCP connection, which allows remote attackers to cause a denial of service (service… | |
| Modificada | Media (5) | 1.3% | — | Novell Iprint | 1/12/2013 | 16/6/2026 | The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to cause a denial of service via unspecified vectors. | |
| Modificada | Media (4.3) | 2.3% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Studio OnsiteNovell Suse Linux Enterprise DebuginfoGraphicsmagick+1 | 23/11/2013 | 16/6/2026 | The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image. | |
| Modificada | Media (6.8) | 0.75% | — | LibguestfsSuse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Server | 5/11/2013 | 16/6/2026 | The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by… | |
| Modificada | Media (6.8) | 1.2% | — | Novell Zenworks Configuration Management | 2/11/2013 | 17/6/2026 | Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (6.8) | 0.58% | — | Novell Zenworks Configuration Management | 2/11/2013 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Alta (10) | 1.5% | — | Novell Zenworks Configuration Management | 2/11/2013 | 17/6/2026 | Unspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors related to an "Application Exception." |