Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.41% | — | Novell Linux DesktopSuse Linux | 9/6/2005 | 16/6/2026 | Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Novell Netmail | 8/6/2005 | 16/6/2026 | Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 3.1% | — | Novell Netmail | 8/6/2005 | 16/6/2026 | Buffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code. | |
| Modificada | Media (4.3) | 2.3% | — | Novell Netmail | 8/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the ModWeb agent for Novell NetMail 3.52 before 3.52C allows remote attackers to inject arbitrary web script or HTML via calendar display fields. | |
| Modificada | Alta (7.5) | 66% | 💥 Exploit | Novell ZenworksNovell Zenworks DesktopsNovell Zenworks Remote ManagementNovell Zenworks Server Management+1 | 25/5/2005 | 16/6/2026 | Multiple stack-based and heap-based buffer overflows in Remote Management authentication (zenrem32.exe) on Novell ZENworks 6.5 Desktop and Server Management, ZENworks for Desktops 4.x, ZENworks for Servers 3.x, and Remote Management allows remote attackers to execute arbitrary code via (1) unspecified vectors, (2)… | |
| Modificada | Baja (2.1) | 0.38% | — | Novell Linux Desktop | 2/5/2005 | 16/6/2026 | tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory. | |
| Modificada | Media (5) | 2.5% | — | Novell Netware | 2/5/2005 | 16/6/2026 | The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start. | |
| Modificada | Media (5) | 2.5% | — | Novell Netware | 2/5/2005 | 16/6/2026 | Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets. | |
| Modificada | Media (5) | 1.8% | — | Novell Ichain | 2/5/2005 | 16/6/2026 | The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command. | |
| Modificada | Alta (7.2) | 0.43% | — | Novell Linux Desktop | 2/5/2005 | 16/6/2026 | Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to "User input [being] passed to network scripts without verification." | |
| Modificada | Alta (10) | 1.9% | — | Novell Ichain | 2/5/2005 | 16/6/2026 | The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows attackers to hijack sessions and gain administrator privileges by (1) sniffing the connection on TCP port 51100 and replaying the authentication information or (2) obtaining and replaying the PCZQX02 authentication cookie from the browser. | |
| Modificada | Alta (7.5) | 1.8% | — | Novell Ichain | 15/3/2005 | 16/6/2026 | Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks. | |
| Modificada | Media (5) | 1.4% | — | Novell Ichain Mini FTP ServerAI | 15/3/2005 | 16/6/2026 | Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks. | |
| Modificada | Media (5) | 2.6% | — | Novell GroupwiseNovell Groupwise Webaccess | 17/1/2005 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the… | |
| Modificada | Media (5) | 2.1% | — | Novell Bordermanager | 31/12/2004 | 16/6/2026 | The Virtual Private Network (VPN) capability in Novell Bordermanager 3.8 allows remote attackers to cause a denial of service (ABEND in IKE.NLM) via a malformed IKE packet, as sent by the Striker ISAKMP Protocol Test Suite. | |
| Modificada | Media (5) | 1.7% | — | Novell Ichain | 31/12/2004 | 16/6/2026 | Novell iChain 2.3 includes the build number in the VIA line of the proxy server's HTTP headers, which allows remote attackers to obtain sensitive information. | |
| Modificada | Alta (10) | 4.0% | — | Novell Netware | 31/12/2004 | 16/6/2026 | webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder. | |
| Modificada | Media (4.3) | 1.2% | — | Novell Ichain | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the failed login page in Novell iChain before 2.2 build 2.2.113 and 2.3 First Customer Ship (FCS) allows remote attackers to inject arbitrary web script or HTML via url parameter. | |
| Modificada | Media (4.3) | 2.1% | — | Novell Netware | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version… | |
| Modificada | Media (5.8) | 1.3% | — | Novell Ichain | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via unspecified vectors. | |
| Modificada | Media (5) | 1.5% | — | Novell Ichain | 31/12/2004 | 16/6/2026 | Novell iChain 2.3 allows attackers to cause a denial of service via a URL with a "specific string." | |
| Modificada | Media (5) | 1.9% | — | Novell Netware | 31/12/2004 | 16/6/2026 | The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt files via a full pathname in the error parameter. | |
| Modificada | Media (6.4) | 1.5% | — | Novell Internet Messaging SystemNovell Netmail | 31/12/2004 | 16/6/2026 | Novell Internet Messaging System (NIMS) 2.6 and 3.0, and NetMail 3.1 and 3.5, is installed with a default NMAP authentication credential, which allows remote attackers to read and write mail store data if the administrator does not change the credential by using the NMAP Credential Generator. | |
| Modificada | Media (5) | 2.3% | — | Novell Netware | 31/12/2004 | 16/6/2026 | Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3) /com/novell/webaccess, or (4) /ns-icons/. | |
| Modificada | Baja (2.1) | 0.40% | — | Novell Netware | 31/12/2004 | 16/6/2026 | Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords. |