Show filters
61 Total Results
Displaying 1-10 of 61
Sort by:
Attacker Value
Very High
CVE-2014-6271
Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
2
Attacker Value
Unknown
Novell ZENworks Admin Studio ISProxy Vulnerability
Disclosure Date: March 29, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers to execute arbitrary local DLL files via a crafted web page that also calls the Initialize method.
0
Attacker Value
Unknown
CVE-2023-6400
Disclosure Date: March 27, 2024 (last updated April 02, 2024)
Incorrect Authorization vulnerability in OpenText™ ZENworks Configuration Management (ZCM) allows Unauthorized Use of Device Resources.This issue affects ZENworks Configuration Management (ZCM) versions: 2020 update 3, 23.3, and 23.4.
0
Attacker Value
Unknown
CVE-2022-38757
Disclosure Date: December 23, 2022 (last updated February 24, 2025)
A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices, to be able to exercise these rights on managed devices in the ZENworks zone but which are outside the scope of the administrator. This vulnerability does not result in the administrators gaining additional rights on the managed devices, either in the scope or outside the scope of the administrator.
0
Attacker Value
Unknown
CVE-2021-22521
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges.
0
Attacker Value
Unknown
CVE-2012-6344
Disclosure Date: January 25, 2020 (last updated February 21, 2025)
Novell ZENworks Configuration Management before 11.2.4 allows XSS.
0
Attacker Value
Unknown
CVE-2012-6345
Disclosure Date: January 25, 2020 (last updated November 28, 2024)
Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.
0
Attacker Value
Unknown
CVE-2015-0785
Disclosure Date: August 09, 2017 (last updated November 08, 2023)
com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders via the dirname variable.
0
Attacker Value
Unknown
CVE-2015-0781
Disclosure Date: August 09, 2017 (last updated November 08, 2023)
Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-0780
Disclosure Date: August 09, 2017 (last updated November 08, 2023)
SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0