Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.1%—Novell Netware31/12/200216/6/2026
Buffer overflow in Novell Remote Manager module, httpstk.nlm, in NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary code via a long (1) username or (2) password.
ModificadaMedia (5)17%💥 ExploitNovell Netware31/12/200216/6/2026
Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3) websinfo.bas, (4) ndslogin.pl, (5) volscgi.pl, (6) lancgi.pl, (7) test.jse, or (8) env.pl.
ModificadaBaja (2.1)0.38%—Novell Netware Client31/12/200216/6/2026
Buffer overflow in Novell NetWare Client 4.80 through 4.83 allows local users to cause a denial of service (crash) by using ping, traceroute, or a similar utility to force the client to resolve a large hostname.
ModificadaCrítica (9.8)2.7%—Novell Edirectory31/12/200216/6/2026
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing.
ModificadaBaja (2.1)0.40%—Novell Netware31/12/200216/6/2026
The Novell Netware client running on Windows 95 allows local users to bypass the login and open arbitrary files via the "What is this?" help feature, which can be launched from the Novell Netware login screen.
ModificadaMedia (4.6)0.39%—Novell Netware31/12/200216/6/2026
Novell Netware 5.0 through 5.1 may allow local users to gain "Domain Admin" rights by logging into a Novell Directory Services (NDS) account, and executing "net use" on an NDS_ADM account that is not in the NT domain but has domain access rights, which allows the user to enter a null password.
ModificadaMedia (5)2.0%—Novell Emframe29/11/200216/6/2026
Desbordamiento de búfer en Novell iManager (eMFrame) anteriores a 1.5 permite a atacantes remotos causar una denegación de servicio mediante una petición de autenticación con un atributo de Nombre Distinguido (DN) largo.
ModificadaMedia (5)2.0%—Novell Emframe4/10/200216/6/2026
Buffer overflow in Novell iManager (eMFrame 1.2.1) allows remote attackers to cause a denial of service (crash) via a long user name.
ModificadaAlta (7.5)3.5%—Novell NetmailNovell Netmail XE4/10/200216/6/2026
Multiple buffer overflows in Novell NetMail (NIMS) 3.0.3 before 3.0.3C allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) WebAdmin or (2) ModWeb.
ModificadaMedia (5)1.9%—Novell Netware4/10/200216/6/2026
Buffer overflows in the DHCP server for NetWare 6.0 SP1 allow remote attackers to cause a denial of service (reboot) via long DHCP requests.
ModificadaMedia (5)1.7%—Novell Netware4/10/200216/6/2026
Format string vulnerability in the FTP server for Novell Netware 6.0 SP1 (NWFTPD) allows remote attackers to cause a denial of service (ABEND) via format strings in the USER command.
ModificadaMedia (5)1.9%—Novell NetmailNovell Netmail XE4/10/200216/6/2026
Buffer overflows in IMAP Agent (imapd) for Novell NetMail (NIMS) 3.0.3 before 3.0.3A allows remote attackers to cause a denial of service.
ModificadaAlta (7.5)3.3%—Novell Groupwise4/10/200216/6/2026
Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.
ModificadaMedia (5)1.7%—Novell Bordermanager12/8/200216/6/2026
Novell BorderManager 3.5 with PAT (Port-Address Translate) enabled allows remote attackers to cause a denial of service by filling the connection table with a large number of connection requests to hosts that do not have a specific route, which may be forwarded to the public interface.
ModificadaMedia (5)1.7%—Novell Bordermanager12/8/200216/6/2026
IP/IPX gateway for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a connection to port 8225 with a large amount of random data, which causes ipipxgw.nlm to ABEND.
ModificadaMedia (5.1)1.1%—Novell WEB Search12/8/200216/6/2026
Cross-site scripting vulnerability in Novell Web Search 2.0.1 allows remote attackers to execute arbitrary script as other Web Search users via the search parameter.
ModificadaMedia (5)1.8%—Novell Bordermanager12/8/200216/6/2026
RTSP proxy for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a GET request to port 9090 followed by a series of carriage returns, which causes proxy.nlm to ABEND.
ModificadaMedia (5)1.7%—Novell Bordermanager12/8/200216/6/2026
FTP proxy server for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service (network connectivity loss) via a connection to port 21 with a large amount of random data.
ModificadaMedia (5)1.7%—Novell Netware12/8/200216/6/2026
Novell Netware FTP server NWFTPD before 5.02r allows remote attackers to cause a denial of service (CPU consumption) via a connection to the server followed by a carriage return, and possibly other invalid commands with improper syntax or length.
ModificadaMedia (5)1.3%—Novell Groupwise25/6/200216/6/2026
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
ModificadaMedia (4.6)0.34%—Novell Groupwise31/5/200216/6/2026
GroupWise 6, cuando se usa autenticación LDAP y cuando Post Office tiene un un nombre de usuario y contraseña en blanco, permite a atacantes ganar privilegios de otros usuaios iniciando una sesión en el sistema sin con contraseña.
ModificadaMedia (5)3.4%💥 ExploitNovell WEB Server15/1/200228/9/2026
Vulnerabilidad en el script files.pl en Novell WebServer Examples Toolkit 2 permite a atacantes remotos leer ficheros arbitrarios.
ModificadaMedia (5)2.9%—Nombas Scriptease WebserverNovell Netware31/12/200116/6/2026
Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows remote attackers to read arbitrary files via ".." sequences in the query string.
ModificadaAlta (7.5)7.3%💥 ExploitNovell Groupwise15/12/200116/6/2026
Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges.
ModificadaMedia (5)4.0%—Novell Groupwise15/10/200116/6/2026
Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.
Orbitaley — Vulnerabilidades