Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.88% | — | Novell Netware Client | 9/1/2008 | 16/6/2026 | NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode. | |
| Modificada | Media (6.8) | 2.0% | — | Novell Apache Http ServerNovell Netware | 21/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in Welcome web-app. | |
| Modificada | Alta (7.5) | 58% | — | Novell Netware Client | 3/12/2006 | 16/6/2026 | Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitrary code via a long argument to the (1) EnumPrinters and (2) OpenPrinter functions. | |
| Modificada | Media (4) | 1.6% | — | Novell Netware | 22/5/2006 | 16/6/2026 | PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password in cleartext to the abend.log log file when the groupOperationsMethod function fails, which allows context-dependent attackers to gain privileges. | |
| Modificada | Media (6.4) | 4.9% | — | Novell Netware | 12/5/2006 | 16/6/2026 | Multiple integer overflows in the DPRPC library (DPRPCNLM.NLM) NDPS/iPrint module in Novell Distributed Print Services in Novell NetWare 6.5 SP3, SP4, and SP5 allow remote attackers to execute arbitrary code via an XDR encoded array with a field that specifies a large number of elements, which triggers the overflows… | |
| Modificada | Media (5) | 2.3% | — | Novell Open Enterprise ServerNovell Netware | 23/3/2006 | 16/6/2026 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) allows a client to force the server to use weak encryption by stating that a weak cipher is required for client compatibility, which might allow remote attackers to decrypt contents of an SSL protected session. | |
| Modificada | Media (5) | 3.2% | — | Novell Open Enterprise ServerNovell Netware | 23/3/2006 | 16/6/2026 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) sometimes selects a weak cipher instead of an available stronger cipher, which makes it easier for remote attackers to sniff and decrypt an SSL protected session. | |
| Modificada | Media (5) | 1.6% | — | Novell Open Enterprise ServerNovell Netware | 23/3/2006 | 16/6/2026 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic. | |
| Modificada | Media (5) | 3.0% | — | Novell Netware FTP ServerNovell Netware | 20/3/2006 | 16/6/2026 | Novell Netware NWFTPD 5.06.05 allows remote attackers to cause a denial of service (ABEND) via an MDTM command that uses a long path for the target file, possibly due to a buffer overflow. | |
| Modificada | Media (5) | 40% | — | Novell Netware | 8/9/2005 | 16/6/2026 | Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a denial of service (ABEND) via an incorrect password length, as exploited by the "worm.rbot.ccc" worm. | |
| Modificada | Media (5) | 2.5% | — | Novell Netware | 2/5/2005 | 16/6/2026 | Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets. | |
| Modificada | Media (5) | 2.5% | — | Novell Netware | 2/5/2005 | 16/6/2026 | The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start. | |
| Modificada | Media (5) | 2.3% | — | Novell Netware | 31/12/2004 | 16/6/2026 | Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3) /com/novell/webaccess, or (4) /ns-icons/. | |
| Modificada | Media (5) | 12% | — | Novell Netware | 31/12/2004 | 16/6/2026 | Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm. | |
| Modificada | Media (5) | 1.9% | — | Novell Netware | 31/12/2004 | 16/6/2026 | The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt files via a full pathname in the error parameter. | |
| Modificada | Alta (10) | 4.0% | — | Novell Netware | 31/12/2004 | 16/6/2026 | webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder. | |
| Modificada | Media (4.3) | 2.1% | — | Novell Netware | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version… | |
| Modificada | Baja (2.1) | 0.40% | — | Novell Netware | 31/12/2004 | 16/6/2026 | Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords. | |
| Modificada | Alta (7.5) | 1.5% | — | Novell Netware | 15/12/2003 | 16/6/2026 | NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount file systems when XNFS should deny the host. | |
| Modificada | Alta (7.5) | 4.1% | — | Novell Zenworks DesktopsNovell Netware | 27/10/2003 | 16/6/2026 | Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors. | |
| Modificada | Media (5) | 14% | — | Novell Netware | 27/8/2003 | 16/6/2026 | Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string. | |
| Modificada | Media (5) | 2.4% | — | Novell Netware | 11/4/2003 | 16/6/2026 | The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option. | |
| Modificada | Media (5) | 2.7% | — | Novell Small Business SuiteNovell Netware | 11/4/2003 | 16/6/2026 | Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to cause a denial of service (ABEND) via a long module name. | |
| Modificada | Alta (7.5) | 3.3% | — | Novell Netware | 11/4/2003 | 16/6/2026 | RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection. | |
| Modificada | Media (5) | 17% | — | Novell Netware | 11/4/2003 | 16/6/2026 | Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences. |