Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 68% | 💥 Exploit | Novell Zenworks Mobile Management | 11/3/2013 | 16/6/2026 | Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote attackers to include and execute arbitrary local files via the language parameter. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Novell Groupwise | 24/2/2013 | 16/6/2026 | The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via unspecified vectors. | |
| Modificada | Alta (9.3) | 39% | 💥 Exploit | Novell Groupwise | 24/2/2013 | 16/6/2026 | An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method. | |
| Modificada | Alta (10) | 4.3% | — | Novell Iprint | 24/12/2012 | 16/6/2026 | Unspecified vulnerability in Novell iPrint Client before 5.82 allows remote attackers to execute arbitrary code via an op-client-interface-version action. | |
| Modificada | Alta (10) | 71% | 💥 Exploit | Novell File Reporter | 18/11/2012 | 16/6/2026 | Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record. | |
| Modificada | Alta (7.8) | 74% | 💥 Exploit | Novell File Reporter | 18/11/2012 | 16/6/2026 | Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record. | |
| Modificada | Alta (7.8) | 68% | 💥 Exploit | Novell File Reporter | 18/11/2012 | 16/6/2026 | Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record. | |
| Modificada | Alta (10) | 38% | — | Novell File Reporter | 18/11/2012 | 16/6/2026 | Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record. | |
| Modificada | Alta (7.8) | 44% | — | Novell Zenworks Asset Management | 20/10/2012 | 16/6/2026 | The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of Scott for the (1) GetFile_Password and (2) GetConfigInfo_Password operations, which allows remote attackers to obtain sensitive information via a crafted… | |
| Modificada | Media (4.3) | 1.5% | — | Novell Groupwise | 28/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to inject arbitrary web script or HTML via a crafted signature in an HTML e-mail message. | |
| Modificada | Media (5) | 42% | — | Novell Groupwise | 28/9/2012 | 16/6/2026 | Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrary files via directory traversal sequences in a request. | |
| Modificada | Alta (9.3) | 3.7% | — | Novell Groupwise | 28/9/2012 | 16/6/2026 | Unspecified vulnerability in the client in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted file. | |
| Modificada | Alta (10) | 5.6% | — | Novell Groupwise | 28/9/2012 | 16/6/2026 | Integer overflow in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Novell Groupwise | 19/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to inject arbitrary web script or HTML via the merge parameter. | |
| Modificada | Alta (10) | 17% | 💥 Exploit | Novell Groupwise | 19/9/2012 | 16/6/2026 | Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow, as demonstrated by a request with -1 in the… | |
| Modificada | Media (4.3) | 3.7% | — | Novell Groupwise | 19/9/2012 | 16/6/2026 | The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted date-time string in a .ics attachment. | |
| Modificada | Baja (2.1) | 0.32% | — | Novell Suse Audit LOG Keeper | 8/8/2012 | 16/6/2026 | The SUSE Audit Log Keeper daemon before 0.2.1-0.4.6.1 for SUSE Manager and Spacewalk uses world-readable permissions for /etc/auditlog-keeper.conf, which allows local users to obtain passwords by reading this file. | |
| Modificada | Media (6.8) | 2.9% | — | Novell Zenworks Configuration Management | 26/7/2012 | 16/6/2026 | Buffer overflow in the DoFindReplace function in the ISGrid.Grid2.1 ActiveX control in InstallShield/ISGrid2.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary code via a long bstrReplaceText parameter. | |
| Modificada | Media (6.8) | 2.7% | — | Novell Zenworks Configuration Management | 26/7/2012 | 16/6/2026 | The ISList.ISAvi ActiveX control in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 provides access to the mscomct2.ocx file, which allows remote attackers to execute arbitrary code by leveraging unspecified mscomct2 flaws. | |
| Modificada | Media (6.8) | 48% | 💥 Exploit | Novell Zenworks Configuration Management | 26/7/2012 | 16/6/2026 | Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary commands via a pathname in the first argument. | |
| Modificada | Media (5) | 3.7% | — | Novell Groupwise | 5/7/2012 | 16/6/2026 | Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attackers to read arbitrary files via the User.interface parameter. | |
| Modificada | Media (6.4) | 8.8% | — | Linux KernelNovell Suse Linux Enterprise Server | 21/6/2012 | 16/6/2026 | The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a… | |
| Modificada | Alta (7.8) | 4.2% | — | Novell Suse Linux Enterprise ServerLinux Kernel | 21/6/2012 | 16/6/2026 | The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to… | |
| Modificada | Baja (1.2) | 0.56% | — | Linux KernelNovell Suse Linux Enterprise ServerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+4 | 13/6/2012 | 16/6/2026 | The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call. | |
| Modificada | Media (4.3) | 1.3% | — | Novell Zenworks Configuration Management | 11/4/2012 | 16/6/2026 | The xplat agent in Novell ZENworks Configuration Management (ZCM) 10.3.x before 10.3.4 and 11.x before 11.2 enables the HTTP TRACE method, which might make it easier for remote attackers to conduct cross-site tracing (XST) attacks via unspecified vectors. |