Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2671▼ 680 respecto a la semana anterior
Críticas / altas1271▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)230▼ 272 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)6.2%—Novell Groupwise8/10/201116/6/2026
Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted TZNAME variable in a VCALENDAR attachment in an e-mail message, related to an "integer…
ModificadaAlta (9.3)3.6%—Novell Cloud Manager6/9/201116/6/2026
The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect privileges associated with a partially initialized session.
ModificadaMedia (4.3)1.2%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted archive file list that is used in an overlay file.
ModificadaAlta (7.5)2.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in the file browser in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename.
ModificadaMedia (4.3)1.2%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RPM info display.
ModificadaAlta (7.5)1.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.
ModificadaAlta (7.5)2.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a filter in a modified file.
ModificadaAlta (7.5)2.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted archive name in the list of testdrive modified files.
ModificadaAlta (7.5)2.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename in the list of testdrive modified files.
ModificadaAlta (7.5)2.7%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename for a custom RPM.
ModificadaMedia (4.3)1.2%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display.
ModificadaMedia (4.3)1.2%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listing.
ModificadaAlta (9.3)1.4%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to have an unknown impact via a crafted directory pathname that is inserted into config.sh.
ModificadaMedia (5)1.2%—Novell Data SynchronizerNovell Mobility Pack9/8/201116/6/2026
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not properly restrict caching of HTTPS responses, which makes it easier for remote attackers to obtain sensitive information by leveraging an unattended workstation.
ModificadaMedia (5)1.2%—Novell Data SynchronizerNovell Mobility Pack9/8/201116/6/2026
WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for remote attackers to obtain access via a brute-force attack.
ModificadaMedia (4.3)1.2%—Novell Data SynchronizerNovell Mobility Pack9/8/201116/6/2026
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
ModificadaMedia (5)1.4%—Novell Data SynchronizerNovell Mobility Pack9/8/201116/6/2026
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
ModificadaMedia (4.3)1.2%—Novell Data SynchronizerNovell Mobility Pack9/8/201116/6/2026
Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors.
ModificadaMedia (5)1.4%—Novell Data SynchronizerNovell Mobility Pack9/8/201116/6/2026
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and obtain sensitive GroupWise information via unspecified vectors.
ModificadaMedia (5)17%—Novell File Reporter17/7/201116/6/2026
NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.
ModificadaAlta (10)16%—Novell File Reporter EngineNovell File Reporter14/7/201116/6/2026
Stack-based buffer overflow in NFREngine.exe in Novell File Reporter Engine before 1.0.2.53, as used in Novell File Reporter and other products, allows remote attackers to execute arbitrary code via a crafted RECORD element.
ModificadaAlta (9.3)5.9%—Novell Iprint9/6/201116/6/2026
Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs cookie.
ModificadaAlta (9.3)4.9%—Novell Iprint9/6/201116/6/2026
Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs parameter in a printer-url.
ModificadaAlta (9.3)5.9%—Novell Iprint9/6/201116/6/2026
Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted iprint-client-config-info parameter in a printer-url.
ModificadaAlta (9.3)5.9%—Novell Iprint9/6/201116/6/2026
Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted client-file-name parameter in a printer-url.
Orbitaley — Vulnerabilidades