Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 28% | 💥 Exploit | Novell Zenworks Configuration Management | 9/4/2012 | 16/6/2026 | Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to read arbitrary files via an opcode 0x21 request. | |
| Modificada | Media (4) | 1.5% | — | Novell Imanager | 9/4/2012 | 16/6/2026 | Buffer overflow in the Create Attribute function in jclient in Novell iManager 2.7.4 before patch 4 allows remote authenticated users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted EnteredAttrName parameter, a related issue to CVE-2010-1929. | |
| Modificada | Alta (10) | 70% | 💥 Exploit | Novell Zenworks Configuration Management | 9/4/2012 | 16/6/2026 | Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x4c request. | |
| Modificada | Alta (10) | 66% | 💥 Exploit | Novell Zenworks Configuration Management | 9/4/2012 | 16/6/2026 | Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x6c request. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Novell Groupwise | 2/3/2012 | 16/6/2026 | The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via a long e-mail address in an Address Book (aka .NAB) file. | |
| Modificada | Alta (10) | 3.8% | — | Novell Iprint | 21/2/2012 | 16/6/2026 | Buffer overflow in the GetDriverSettings function in nipplib.dll in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code via a long realm field, a different vulnerability than CVE-2011-3173. | |
| Modificada | Alta (9.3) | 3.4% | — | Novell Iprint | 21/2/2012 | 16/6/2026 | Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code via a crafted client-file-name parameter in a printer-url, a different vulnerability than CVE-2011-1705. | |
| Modificada | Alta (10) | 3.3% | — | Novell Iprint | 21/2/2012 | 16/6/2026 | The GetPrinterURLList2 method in the ActiveX control in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2008-2431 and CVE-2008-2436. | |
| Modificada | Alta (7.5) | 3.0% | — | Novell Open Enterprise Server | 2/2/2012 | 16/6/2026 | Buffer overflow in Novell iPrint Server in Novell Open Enterprise Server 2 (OES2) through SP3 on Linux allows remote attackers to execute arbitrary code via a crafted attributes-natural-language field. | |
| Modificada | Alta (7.5) | 3.5% | — | Novell Xtier Framework | 31/12/2011 | 16/6/2026 | Multiple integer overflows in the HTTP server in the Novell XTier framework 3.1.8 allow remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via crafted header length variables. | |
| Modificada | Media (4) | 3.2% | 💥 Exploit | Novell Sentinel LOG Manager | 29/12/2011 | 16/6/2026 | Directory traversal vulnerability in novelllogmanager/FileDownload in Novell Sentinel Log Manager 1.2.0.1_938 and earlier, as used in Novell Sentinel before 7.0.1.0, allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter. | |
| Modificada | Media (5) | 1.2% | — | Novell Groupwise MessengerNovell Messenger | 8/12/2011 | 16/6/2026 | The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.04 and earlier, allows remote attackers to read from arbitrary memory locations via a crafted command. | |
| Modificada | Alta (10) | 72% | 💥 Exploit | Novell Zenworks Asset Management | 8/12/2011 | 16/6/2026 | Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote attackers to execute arbitrary code by uploading an executable file. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Novell Netware | 30/11/2011 | 16/6/2026 | Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (abend or NFS outage) via long packets. | |
| Modificada | Alta (7.5) | 4.8% | — | Novell Iprint Open Enterprise Server 2 | 30/11/2011 | 16/6/2026 | Stack-based buffer overflow in the GetDriverSettings function in nipplib.dll in the iPrint client in Novell Open Enterprise Server 2 (aka OES2) SP3 allows remote attackers to execute arbitrary code via a long (1) hostname or (2) port field. | |
| Modificada | Alta (9.3) | 3.5% | — | Novell Zenworks Handheld Management | 24/10/2011 | 16/6/2026 | Unspecified vulnerability in ZfHSrvr.exe in Novell ZENworks Handheld Management (ZHM) 7 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2655. | |
| Modificada | Alta (9.3) | 3.5% | — | Novell Zenworks Handheld Management | 24/10/2011 | 16/6/2026 | Unspecified vulnerability in ZfHSrvr.exe in Novell ZENworks Handheld Management (ZHM) 7 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2656. | |
| Modificada | Alta (10) | 5.5% | — | Novell Groupwise | 8/10/2011 | 16/6/2026 | Array index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted yearly RRULE variable in a VCALENDAR attachment in an e-mail message. | |
| Modificada | Alta (10) | 4.1% | — | Novell Groupwise | 8/10/2011 | 16/6/2026 | Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a negative BYWEEKNO property in a weekly RRULE variable in a VCALENDAR attachment in an e-mail message. | |
| Modificada | Media (4.3) | 0.94% | — | Novell Groupwise | 8/10/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Directory.Item.name or (2) Directory.Item.displayName parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Novell Identity Manager Roles Based Provisioning ModuleNovell Identity Manager User Application | 8/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka… | |
| Modificada | Media (5) | 1.1% | — | Novell Groupwise | 8/10/2011 | 16/6/2026 | Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2218. | |
| Modificada | Media (5) | 1.1% | — | Novell Groupwise | 8/10/2011 | 16/6/2026 | Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2219. | |
| Modificada | Media (4.3) | 1.7% | — | Novell Identity Manager Roles Based Provisioning ModuleNovell Identity Manager User Application | 8/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka… | |
| Modificada | Alta (10) | 4.8% | — | Novell Groupwise | 8/10/2011 | 16/6/2026 | Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file. |