Show filters
655 Total Results
Displaying 41-50 of 655
Sort by:
Attacker Value
Unknown

CVE-2016-5760

Disclosure Date: April 20, 2017 (last updated November 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/install/login.jsp or (2) PATH_INFO to gwadmin-console/index.jsp.
0
Attacker Value
Unknown

CVE-2016-9168

Disclosure Date: March 23, 2017 (last updated November 08, 2023)
A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.
0
Attacker Value
Unknown

CVE-2016-9167

Disclosure Date: March 23, 2017 (last updated November 08, 2023)
NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL.
0
Attacker Value
Unknown

CVE-2016-5747

Disclosure Date: March 23, 2017 (last updated November 08, 2023)
A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies.
0
Attacker Value
Unknown

CVE-2016-9169

Disclosure Date: March 23, 2017 (last updated November 08, 2023)
A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScript in the context of a valid user's browser session by getting the user to click on a specially crafted link. This could lead to session compromise or other browser-based attacks.
0
Attacker Value
Unknown

CVE-2016-1603

Disclosure Date: March 23, 2017 (last updated November 08, 2023)
An information leak in the NetIQ IDM ServiceNow Driver before 1.0.0.1 could expose cryptographic attributes to logged-in users.
0
Attacker Value
Unknown

CVE-2014-9853

Disclosure Date: March 17, 2017 (last updated November 05, 2024)
Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
Attacker Value
Unknown

CVE-2010-4314

Disclosure Date: March 11, 2017 (last updated November 08, 2023)
Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overflowing the "name" parameter.
0
Attacker Value
Unknown

CVE-2015-7976

Disclosure Date: January 30, 2017 (last updated November 25, 2024)
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
0
Attacker Value
Unknown

CVE-2017-5182

Disclosure Date: January 23, 2017 (last updated November 08, 2023)
Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that allows complete directory traversal and total information disclosure. This vulnerability is present on all versions of OES for linux, it applies to OES2015 SP1 before Maintenance Update 11080, OES2015 before Maintenance Update 11079, OES11 SP3 before Maintenance Update 11078, OES11 SP2 before Maintenance Update 11077).
0