Novell
Novell Netware: vulnerabilities and CVEs
Novell Netware has 72 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs72
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-4191 | High (7.5) | 10% | — | Nov 30, 2011 | Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (abend or NFS outage) via long packets. |
| CVE-2010-4228 | High (9) | 15% | — | Mar 22, 2011 | Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary code or cause a denial of service (abend) via a long DELE command, a… |
| CVE-2010-4227 | High (10) | 17% | — | Feb 25, 2011 | The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port… |
| CVE-2010-2351 | High (10) | 16% | — | Jun 21, 2010 | Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitrary code via a Sessions Setup AndX packet with a long AccountName. |
| CVE-2010-0625 | Medium (6.5) | 5.1% | — | Apr 5, 2010 | Stack-based buffer overflow in NWFTPD.nlm before 5.10.01 in the FTP server in Novell NetWare 5.1 through 6.5 SP8 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute… |
| CVE-2007-6735 | High (7.5) | 1.9% | — | Apr 5, 2010 | NWFTPD.nlm before 5.08.06 in the FTP server in Novell NetWare does not properly handle partial matches for container names in the FTPREST.TXT file, which allows remote attackers to bypass intended access restrictions… |
| CVE-2007-6734 | Medium (4) | 1.4% | — | Apr 5, 2010 | NWFTPD.nlm before 5.08.07 in the FTP server in Novell NetWare 6.5 SP7 does not properly implement the FTPREST.TXT NOREMOTE restriction, which allows remote authenticated users to access directories outside of the home… |
| CVE-2005-4888 | Medium (5) | 1.7% | — | Apr 5, 2010 | NWFTPD.nlm before 5.06.04 in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (excessive stale connections) by establishing many FTP sessions, which persist in the Not-Logged-In… |
| CVE-2005-4887 | High (7.5) | 1.4% | — | Apr 5, 2010 | NWFTPD.nlm before 5.06.05 in the FTP server in Novell NetWare 6.5 SP5 allows attackers to have an unspecified impact via vectors related to passwords. |
| CVE-2004-2767 | Medium (4.3) | 1.5% | — | Apr 5, 2010 | NWFTPD.nlm before 5.04.25 in the FTP server in Novell NetWare does not promptly close DS sessions, which allows remote attackers to cause a denial of service (connection slot exhaustion) by establishing many FTP… |
| CVE-2003-1596 | High (7.5) | 2.0% | — | Apr 5, 2010 | NWFTPD.nlm before 5.03.12 in the FTP server in Novell NetWare does not properly restrict filesystem use by anonymous users with NFS Gateway home directories, which allows remote attackers to bypass intended access… |
| CVE-2003-1595 | High (10) | 1.7% | — | Apr 5, 2010 | NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly perform "intruder detection," which has unspecified impact and attack vectors. |
| CVE-2003-1594 | High (7.5) | 1.9% | — | Apr 5, 2010 | NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly enforce FTPREST.TXT settings, which allows remote attackers to bypass intended access restrictions via an FTP session. |
| CVE-2003-1593 | High (7.5) | 1.9% | — | Apr 5, 2010 | NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 does not enforce domain-name login restrictions, which allows remote attackers to bypass intended access control via an FTP connection. |
| CVE-2003-1592 | Medium (5) | 1.7% | — | Apr 5, 2010 | Multiple buffer overflows in NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allow remote attackers to cause a denial of service (abend) via a long (1) username or (2) password. |
| CVE-2003-1591 | Medium (4.3) | 1.5% | — | Apr 5, 2010 | NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allows user-assisted remote attackers to cause a denial of service (console hang) via a large number of FTP sessions, which are not… |
| CVE-2002-2434 | Medium (5) | 1.7% | — | Apr 5, 2010 | NWFTPD.nlm before 5.02i in the FTP server in Novell NetWare does not properly listen for data connections, which allows remote attackers to cause a denial of service (abend) via multiple FTP sessions. |
| CVE-2002-2433 | Medium (4) | 1.4% | — | Apr 5, 2010 | NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote authenticated users to cause a denial of service (abend) via a crafted ABOR command. |
| CVE-2002-2432 | Medium (5) | 1.7% | — | Apr 5, 2010 | Unspecified vulnerability in NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via a crafted username. |
| CVE-2001-1587 | Medium (5) | 1.1% | — | Apr 5, 2010 | NWFTPD.nlm before 5.01w in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via an anonymous STOU command. |
| CVE-2000-1246 | Low (3.5) | 0.81% | — | Apr 5, 2010 | NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allows remote authenticated users to cause a denial of service (abend) by sending an RNTO command after a failed RNFR command. |
| CVE-2000-1245 | High (7.5) | 1.3% | — | Apr 5, 2010 | Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors. |
| CVE-2010-0317 | High (7.8) | 10% | — | Jan 15, 2010 | Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP requests that are not properly handled… |
| CVE-2008-5696 | High (9.3) | 3.3% | — | Dec 19, 2008 | Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP… |
| CVE-2006-6675 | Medium (6.8) | 2.0% | — | Dec 21, 2006 | Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in… |
| CVE-2006-2185 | Medium (4) | 1.6% | — | May 22, 2006 | PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password in cleartext to the abend.log log file when the groupOperationsMethod function fails, which allows context-dependent attackers to gain privileges. |
| CVE-2006-2327 | Medium (6.4) | 4.9% | — | May 12, 2006 | Multiple integer overflows in the DPRPC library (DPRPCNLM.NLM) NDPS/iPrint module in Novell Distributed Print Services in Novell NetWare 6.5 SP3, SP4, and SP5 allow remote attackers to execute arbitrary code via an XDR… |
| CVE-2006-0998 | Medium (5) | 3.2% | — | Mar 23, 2006 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) sometimes selects a weak cipher instead of an available stronger cipher, which makes it easier for remote attackers… |
| CVE-2006-0997 | Medium (5) | 1.6% | — | Mar 23, 2006 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read… |
| CVE-2006-0999 | Medium (5) | 2.3% | — | Mar 23, 2006 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) allows a client to force the server to use weak encryption by stating that a weak cipher is required for client… |
Other products by Novell
Suse Linux Enterprise Server · 91Suse Linux Enterprise Desktop · 83Groupwise · 75Suse Linux Enterprise Software Development KIT · 65Edirectory · 51Zenworks Configuration Management · 35Suse Linux Enterprise Real Time Extension · 33Iprint · 30Suse Linux Enterprise Debuginfo · 24Suse Linux Enterprise Workstation Extension · 24Suse Linux Enterprise Module FOR Public Cloud · 22Suse Linux Enterprise Live Patching · 22