Show filters
655 Total Results
Displaying 41-50 of 655
Sort by:
Attacker Value
Unknown
CVE-2016-5760
Disclosure Date: April 20, 2017 (last updated November 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/install/login.jsp or (2) PATH_INFO to gwadmin-console/index.jsp.
0
Attacker Value
Unknown
CVE-2016-9168
Disclosure Date: March 23, 2017 (last updated November 08, 2023)
A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.
0
Attacker Value
Unknown
CVE-2016-9167
Disclosure Date: March 23, 2017 (last updated November 08, 2023)
NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL.
0
Attacker Value
Unknown
CVE-2016-5747
Disclosure Date: March 23, 2017 (last updated November 08, 2023)
A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies.
0
Attacker Value
Unknown
CVE-2016-9169
Disclosure Date: March 23, 2017 (last updated November 08, 2023)
A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScript in the context of a valid user's browser session by getting the user to click on a specially crafted link. This could lead to session compromise or other browser-based attacks.
0
Attacker Value
Unknown
CVE-2016-1603
Disclosure Date: March 23, 2017 (last updated November 08, 2023)
An information leak in the NetIQ IDM ServiceNow Driver before 1.0.0.1 could expose cryptographic attributes to logged-in users.
0
Attacker Value
Unknown
CVE-2014-9853
Disclosure Date: March 17, 2017 (last updated November 05, 2024)
Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
0
Attacker Value
Unknown
CVE-2010-4314
Disclosure Date: March 11, 2017 (last updated November 08, 2023)
Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overflowing the "name" parameter.
0
Attacker Value
Unknown
CVE-2015-7976
Disclosure Date: January 30, 2017 (last updated November 25, 2024)
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
0
Attacker Value
Unknown
CVE-2017-5182
Disclosure Date: January 23, 2017 (last updated November 08, 2023)
Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that allows complete directory traversal and total information disclosure. This vulnerability is present on all versions of OES for linux, it applies to OES2015 SP1 before Maintenance Update 11080, OES2015 before Maintenance Update 11079, OES11 SP3 before Maintenance Update 11078, OES11 SP2 before Maintenance Update 11077).
0