Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.3%—Novell Open Enterprise ServerNovell Netware23/3/200616/6/2026
La implementación del servidor SSL en NILE.NLM en Novell NetWare 6.5 y Novell Open Enterprise Server (OES) permite a un cliente forzar el servidor para usar cifrado débil afirmando que se requiere un cifrado débil para la compatibilidad del cliente, lo que podría permitir a atacantes remotos descifrar contenidos de…
ModificadaMedia (5)3.0%—Novell Netware FTP ServerNovell Netware20/3/200616/6/2026
Novell Netware NWFTPD 5.06.05 allows remote attackers to cause a denial of service (ABEND) via an MDTM command that uses a long path for the target file, possibly due to a buffer overflow.
ModificadaMedia (5)1.6%—Novell Bordermanager14/3/200616/6/2026
Unspecified vulnerability in the HTTP proxy in Novell BorderManager 3.8 and earlier allows remote attackers to cause a denial of service (CPU consumption and ABEND) via unknown attack vectors related to "media streaming over HTTP 1.1".
ModificadaAlta (10)7.1%—Novell Linux DesktopNovell Open Enterprise Server27/2/200616/6/2026
Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (5)1.8%—Novell Suse LinuxSuse Linux23/2/200616/6/2026
The signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is not intended for signature verification, which prevents YOU from detecting malicious scripts or code that do not pass the signature check when gpg 1.4.x is being used.
ModificadaBaja (1.7)0.41%—Novell Netmail31/12/200516/6/2026
Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files.
ModificadaAlta (9.3)4.8%—Novell Imanager31/12/200516/6/2026
Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.
ModificadaBaja (2.1)0.44%—Novell Suse Linux31/12/200516/6/2026
Multiple untrusted search path vulnerabilities in SUSE Linux 10.0 cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) liferea or (2) banshee.
ModificadaAlta (7.5)5.7%—Novell Open Enterprise Server31/12/200516/6/2026
Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (novell-nrm) in Novell SUSE Linux Enterprise Server 9 allows remote attackers to execute arbitrary code via an HTTP POST request with a negative Content-Length parameter.
ModificadaMedia (6.9)0.48%—Novell Suse LinuxSuse Linux31/12/200516/6/2026
Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported…
ModificadaMedia (4.6)0.34%—Novell ZenworksNovell Zenworks DesktopsNovell Zenworks Servers23/11/200516/6/2026
Novell ZENworks for Desktops 4.0.1, ZENworks for Servers 3.0.2, and ZENworks 6.5 Desktop Management does not restrict access to Remote Diagnostics, which allows local users to bypass security policies by using Console One.
ModificadaAlta (7.5)66%💥 ExploitNovell Netmail18/11/200516/6/2026
Stack-based buffer overflow in the IMAP daemon in Novell Netmail 3.5.2 allows remote attackers to execute arbitrary code via "long verb arguments."
ModificadaAlta (7.5)5.4%💥 ExploitNovell Zenworks Patch Management Server30/10/200516/6/2026
Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, and (4) computerFilter parameters to reports/default.asp.
ModificadaMedia (4.6)0.40%—Novell Suse LinuxSuse Linux27/10/200516/6/2026
chkstat in SuSE Linux 9.0 through 10.0 allows local users to modify permissions of files by creating a hardlink to a file from a world-writable directory, which can cause the link count to drop to 1 when the file is deleted or replaced, which is then modified by chkstat to use weaker permissions.
ModificadaMedia (4.6)0.51%—Novell Netmail20/10/200516/6/2026
Stack-based buffer overflow in the NMAP Agent for Novell NetMail 3.52C and possibly earlier versions allows local users to execute arbitrary code via a long user name in the USER command.
ModificadaMedia (5)5.1%💥 ExploitNovell Groupwise4/10/200516/6/2026
Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key.
ModificadaMedia (5)40%💥 ExploitNovell Netware8/9/200516/6/2026
Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a denial of service (ABEND) via an incorrect password length, as exploited by the "worm.rbot.ccc" worm.
ModificadaMedia (5)2.0%—Novell Groupwise17/8/200516/6/2026
grpWise.exe for Novell GroupWise client 5.5 through 6.5.2 stores the password in plaintext in memory, which allows attackers to obtain the password using a debugger or another mechanism to read process memory.
ModificadaAlta (7.5)55%💥 ExploitNovell Edirectory12/8/200516/6/2026
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.
ModificadaBaja (2.1)0.46%—Novell Open Enterprise ServerNovell Linux DesktopSuse Linux5/8/200516/6/2026
Vulnerabilidad desconocida en el kernel de Linux 2.6.x y 2.4.x permite que usuarios locales provoquen una denegación de servicio ("stack fault exception") mediante métodos desconocidos.
ModificadaBaja (2.1)0.46%—Novell Open Enterprise ServerNovell Linux DesktopSuse Linux5/8/200516/6/2026
Vulnerabilidad desconocida en el kernel de Linux permite que usuarios locales provoquen una denegación de servicio mediante ptrace
ModificadaAlta (7.5)2.7%—Novell Groupwise3/8/200516/6/2026
Desbordamiento de búfer en Cliente Novell GroupWise 6.5 permite que atacantes remotos ejecuten código arbitrario mediante un fichero de lenguaje GWVW02xx.INI con una entrada larga (como se demuestra usando un valor largo para ESO2TKS.VEW en la sección Group Task).
ModificadaMedia (4.3)2.5%💥 ExploitNovell Groupwise Webaccess26/7/200516/6/2026
Vulnerabilidad de secuencia de comandos en sitios cruzados en Novell Groupwise WebAccess 6.5 anterior a July 11, 2005 permite que atacantes remotos inyecten script web arbitrario o HTML mediante un mensaje de correo con un javascript codificado en un URI (e.g. "jAvascript" en una etiqueta IMG).
ModificadaMedia (6.4)3.5%💥 ExploitNovell Netmail9/7/200516/6/2026
Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
ModificadaMedia (5)1.6%—Novell Edirectory12/6/200516/6/2026
Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1.
Orbitaley — Vulnerabilidades