Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.3% | — | Novell Open Enterprise ServerNovell Netware | 23/3/2006 | 16/6/2026 | La implementación del servidor SSL en NILE.NLM en Novell NetWare 6.5 y Novell Open Enterprise Server (OES) permite a un cliente forzar el servidor para usar cifrado débil afirmando que se requiere un cifrado débil para la compatibilidad del cliente, lo que podría permitir a atacantes remotos descifrar contenidos de… | |
| Modificada | Media (5) | 3.0% | — | Novell Netware FTP ServerNovell Netware | 20/3/2006 | 16/6/2026 | Novell Netware NWFTPD 5.06.05 allows remote attackers to cause a denial of service (ABEND) via an MDTM command that uses a long path for the target file, possibly due to a buffer overflow. | |
| Modificada | Media (5) | 1.6% | — | Novell Bordermanager | 14/3/2006 | 16/6/2026 | Unspecified vulnerability in the HTTP proxy in Novell BorderManager 3.8 and earlier allows remote attackers to cause a denial of service (CPU consumption and ABEND) via unknown attack vectors related to "media streaming over HTTP 1.1". | |
| Modificada | Alta (10) | 7.1% | — | Novell Linux DesktopNovell Open Enterprise Server | 27/2/2006 | 16/6/2026 | Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5) | 1.8% | — | Novell Suse LinuxSuse Linux | 23/2/2006 | 16/6/2026 | The signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is not intended for signature verification, which prevents YOU from detecting malicious scripts or code that do not pass the signature check when gpg 1.4.x is being used. | |
| Modificada | Baja (1.7) | 0.41% | — | Novell Netmail | 31/12/2005 | 16/6/2026 | Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files. | |
| Modificada | Alta (9.3) | 4.8% | — | Novell Imanager | 31/12/2005 | 16/6/2026 | Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112. | |
| Modificada | Baja (2.1) | 0.44% | — | Novell Suse Linux | 31/12/2005 | 16/6/2026 | Multiple untrusted search path vulnerabilities in SUSE Linux 10.0 cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) liferea or (2) banshee. | |
| Modificada | Alta (7.5) | 5.7% | — | Novell Open Enterprise Server | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (novell-nrm) in Novell SUSE Linux Enterprise Server 9 allows remote attackers to execute arbitrary code via an HTTP POST request with a negative Content-Length parameter. | |
| Modificada | Media (6.9) | 0.48% | — | Novell Suse LinuxSuse Linux | 31/12/2005 | 16/6/2026 | Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported… | |
| Modificada | Media (4.6) | 0.34% | — | Novell ZenworksNovell Zenworks DesktopsNovell Zenworks Servers | 23/11/2005 | 16/6/2026 | Novell ZENworks for Desktops 4.0.1, ZENworks for Servers 3.0.2, and ZENworks 6.5 Desktop Management does not restrict access to Remote Diagnostics, which allows local users to bypass security policies by using Console One. | |
| Modificada | Alta (7.5) | 66% | 💥 Exploit | Novell Netmail | 18/11/2005 | 16/6/2026 | Stack-based buffer overflow in the IMAP daemon in Novell Netmail 3.5.2 allows remote attackers to execute arbitrary code via "long verb arguments." | |
| Modificada | Alta (7.5) | 5.4% | 💥 Exploit | Novell Zenworks Patch Management Server | 30/10/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, and (4) computerFilter parameters to reports/default.asp. | |
| Modificada | Media (4.6) | 0.40% | — | Novell Suse LinuxSuse Linux | 27/10/2005 | 16/6/2026 | chkstat in SuSE Linux 9.0 through 10.0 allows local users to modify permissions of files by creating a hardlink to a file from a world-writable directory, which can cause the link count to drop to 1 when the file is deleted or replaced, which is then modified by chkstat to use weaker permissions. | |
| Modificada | Media (4.6) | 0.51% | — | Novell Netmail | 20/10/2005 | 16/6/2026 | Stack-based buffer overflow in the NMAP Agent for Novell NetMail 3.52C and possibly earlier versions allows local users to execute arbitrary code via a long user name in the USER command. | |
| Modificada | Media (5) | 5.1% | 💥 Exploit | Novell Groupwise | 4/10/2005 | 16/6/2026 | Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key. | |
| Modificada | Media (5) | 40% | 💥 Exploit | Novell Netware | 8/9/2005 | 16/6/2026 | Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a denial of service (ABEND) via an incorrect password length, as exploited by the "worm.rbot.ccc" worm. | |
| Modificada | Media (5) | 2.0% | — | Novell Groupwise | 17/8/2005 | 16/6/2026 | grpWise.exe for Novell GroupWise client 5.5 through 6.5.2 stores the password in plaintext in memory, which allows attackers to obtain the password using a debugger or another mechanism to read process memory. | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Novell Edirectory | 12/8/2005 | 16/6/2026 | Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors. | |
| Modificada | Baja (2.1) | 0.46% | — | Novell Open Enterprise ServerNovell Linux DesktopSuse Linux | 5/8/2005 | 16/6/2026 | Vulnerabilidad desconocida en el kernel de Linux 2.6.x y 2.4.x permite que usuarios locales provoquen una denegación de servicio ("stack fault exception") mediante métodos desconocidos. | |
| Modificada | Baja (2.1) | 0.46% | — | Novell Open Enterprise ServerNovell Linux DesktopSuse Linux | 5/8/2005 | 16/6/2026 | Vulnerabilidad desconocida en el kernel de Linux permite que usuarios locales provoquen una denegación de servicio mediante ptrace | |
| Modificada | Alta (7.5) | 2.7% | — | Novell Groupwise | 3/8/2005 | 16/6/2026 | Desbordamiento de búfer en Cliente Novell GroupWise 6.5 permite que atacantes remotos ejecuten código arbitrario mediante un fichero de lenguaje GWVW02xx.INI con una entrada larga (como se demuestra usando un valor largo para ESO2TKS.VEW en la sección Group Task). | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Novell Groupwise Webaccess | 26/7/2005 | 16/6/2026 | Vulnerabilidad de secuencia de comandos en sitios cruzados en Novell Groupwise WebAccess 6.5 anterior a July 11, 2005 permite que atacantes remotos inyecten script web arbitrario o HTML mediante un mensaje de correo con un javascript codificado en un URI (e.g. "jAvascript" en una etiqueta IMG). | |
| Modificada | Media (6.4) | 3.5% | 💥 Exploit | Novell Netmail | 9/7/2005 | 16/6/2026 | Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies. | |
| Modificada | Media (5) | 1.6% | — | Novell Edirectory | 12/6/2005 | 16/6/2026 | Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1. |