Novell
Novell Open Enterprise Server: vulnerabilities and CVEs
Novell Open Enterprise Server has 20 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 2 are listed by CISA as actively exploited.
CVEs20
Last 12 months0
Critical2
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-6271 | Critical (9.8) | 100% | ⚠ Active exploitation | Sep 24, 2014 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by… |
| CVE-2014-7169 | Critical (9.8) | 100% | ⚠ Active exploitation | Sep 25, 2014 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-2016 | High (7.8) | 0.51% | — | Dec 30, 2019 | A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a… |
| CVE-2017-5182 | High (7.5) | 3.2% | — | Jan 23, 2017 | Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that allows complete directory traversal and total information disclosure.… |
| CVE-2014-7169 | Critical (9.8) | 100% | ⚠ Active exploitation | Sep 25, 2014 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown… |
| CVE-2014-6271 | Critical (9.8) | 100% | ⚠ Active exploitation | Sep 24, 2014 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by… |
| CVE-2014-0609 | High (10) | 2.2% | — | Aug 17, 2014 | Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintenance Update 9413 for Linux has unknown impact and attack vectors. |
| CVE-2014-0599 | Medium (4.3) | 2.0% | — | Jun 18, 2014 | Cross-site scripting (XSS) vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified… |
| CVE-2014-0598 | High (10) | 2.5% | — | Jun 18, 2014 | Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified impact and remote attack vectors. |
| CVE-2014-0595 | Low (2.6) | 0.34% | — | May 8, 2014 | /opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic… |
| CVE-2013-3707 | Medium (4.3) | 1.6% | — | Dec 1, 2013 | The HTTPSTK service in the novell-nrm package before 2.0.2-297.305.302.3 in Novell Open Enterprise Server 2 (OES 2) Linux, and OES 11 Linux Gold and SP1, does not make the intended SSL_free and SSL_shutdown calls for… |
| CVE-2011-4194 | High (7.5) | 3.0% | — | Feb 2, 2012 | Buffer overflow in Novell iPrint Server in Novell Open Enterprise Server 2 (OES2) through SP3 on Linux allows remote attackers to execute arbitrary code via a crafted attributes-natural-language field. |
| CVE-2009-0115 | High (7.8) | 0.49% | — | Mar 30, 2009 | The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses… |
| CVE-2009-0611 | Medium (4.3) | 2.2% | — | Feb 17, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary web script or HTML via (1) the siteloc… |
| CVE-2008-5021 | High (9.3) | 3.6% | — | Nov 13, 2008 | nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute… |
| CVE-2006-0997 | Medium (5) | 1.6% | — | Mar 23, 2006 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read… |
| CVE-2006-0999 | Medium (5) | 2.3% | — | Mar 23, 2006 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) allows a client to force the server to use weak encryption by stating that a weak cipher is required for client… |
| CVE-2006-0998 | Medium (5) | 3.2% | — | Mar 23, 2006 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) sometimes selects a weak cipher instead of an available stronger cipher, which makes it easier for remote attackers… |
| CVE-2006-0736 | High (10) | 7.1% | — | Feb 27, 2006 | Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors. |
| CVE-2005-3655 | High (7.5) | 5.7% | — | Dec 31, 2005 | Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (novell-nrm) in Novell SUSE Linux Enterprise Server 9 allows remote attackers to execute arbitrary code via an HTTP POST request with a negative… |
| CVE-2005-1767 | Low (2.1) | 0.46% | — | Aug 5, 2005 | traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, which allows local users to cause a denial of service (oops and stack fault exception). |
| CVE-2005-1761 | Low (2.1) | 0.46% | — | Aug 5, 2005 | Linux kernel 2.6 and 2.4 on the IA64 architecture allows local users to cause a denial of service (kernel crash) via ptrace and the restore_sigcontext function. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.
Other products by Novell
Suse Linux Enterprise Server · 91Suse Linux Enterprise Desktop · 83Groupwise · 75Netware · 72Suse Linux Enterprise Software Development KIT · 65Edirectory · 51Zenworks Configuration Management · 35Suse Linux Enterprise Real Time Extension · 33Iprint · 30Suse Linux Enterprise Debuginfo · 24Suse Linux Enterprise Workstation Extension · 24Suse Linux Enterprise Module FOR Public Cloud · 22