Show filters
80 Total Results
Displaying 21-30 of 80
Sort by:
Attacker Value
Unknown

CVE-2003-1596

Disclosure Date: April 05, 2010 (last updated October 04, 2023)
NWFTPD.nlm before 5.03.12 in the FTP server in Novell NetWare does not properly restrict filesystem use by anonymous users with NFS Gateway home directories, which allows remote attackers to bypass intended access restrictions via an FTP session.
0
Attacker Value
Unknown

CVE-2001-1587

Disclosure Date: April 05, 2010 (last updated October 04, 2023)
NWFTPD.nlm before 5.01w in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via an anonymous STOU command.
0
Attacker Value
Unknown

CVE-2007-6735

Disclosure Date: April 05, 2010 (last updated October 04, 2023)
NWFTPD.nlm before 5.08.06 in the FTP server in Novell NetWare does not properly handle partial matches for container names in the FTPREST.TXT file, which allows remote attackers to bypass intended access restrictions via an FTP session.
0
Attacker Value
Unknown

CVE-2010-0317

Disclosure Date: January 15, 2010 (last updated October 04, 2023)
Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP requests that are not properly handled by (1) the CIFS functionality in CIFS.nlm Semantic Agent (Build 163 MP) 3.27 or (2) the AFP functionality in AFPTCP.nlm Build 163 SP 3.27. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-5696

Disclosure Date: December 19, 2008 (last updated October 04, 2023)
Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.
0
Attacker Value
Unknown

CVE-2007-5762

Disclosure Date: January 09, 2008 (last updated October 04, 2023)
NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode.
0
Attacker Value
Unknown

CVE-2007-0851

Disclosure Date: February 08, 2007 (last updated October 04, 2023)
Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable.
0
Attacker Value
Unknown

CVE-2006-6675

Disclosure Date: December 21, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in Welcome web-app.
0
Attacker Value
Unknown

CVE-2006-5854

Disclosure Date: December 03, 2006 (last updated October 04, 2023)
Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitrary code via a long argument to the (1) EnumPrinters and (2) OpenPrinter functions.
0
Attacker Value
Unknown

CVE-2006-2185

Disclosure Date: May 22, 2006 (last updated October 04, 2023)
PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password in cleartext to the abend.log log file when the groupOperationsMethod function fails, which allows context-dependent attackers to gain privileges.
0