cbcvebase.

Novell Netware vulnerabilities

63 known vulnerabilities affecting novell/netware.

Total CVEs
63
CISA KEV
0
Public exploits
14
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH15MEDIUM39LOW2

Vulnerabilities

Page 1 of 4
CVE-2001-1580P2MEDIUMCVSS 5.0Exploitedv5.12001-12-31
CVE-2001-1580 [MEDIUM] CVE-2001-1580: Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows r Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows remote attackers to read arbitrary files via ".." sequences in the query string.
nvd
CVE-2010-2351P2CRITICALCVSS 10.0PoC≤ 6.5v5.0+3 more2010-06-21
CVE-2010-2351 [CRITICAL] CWE-119 CVE-2010-2351: Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitrary code via a Sessions Setup AndX packet with a long AccountName.
nvd
CVE-2010-4227P2CRITICALCVSS 10.0PoC≤ 6.5v6.52011-02-25
CVE-2010-4227 [CRITICAL] CWE-119 CVE-2010-4227: The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port UDP 1234, leading to a stack-based buffer overflow.
nvd
CVE-2010-4228P3CRITICALCVSS 9.0PoCv5.1v6.0+1 more2011-03-22
CVE-2010-4228 [CRITICAL] CVE-2010-4228: Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary code or cause a denial of service (abend) via a long DELE command, a different vulnerability than CVE-2010-0625.4.
nvd
CVE-2011-4191P3HIGHCVSS 7.5PoCv6.52011-11-30
CVE-2011-4191 [HIGH] CWE-119 CVE-2011-4191: Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 al Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (abend or NFS outage) via long packets.
nvd
CVE-2002-1436P3HIGHCVSS 7.5PoCv5.1v6.02003-04-11
CVE-2002-1436 [HIGH] CVE-2002-1436: The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execut The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.
nvd
CVE-2010-0317P3HIGHCVSS 7.8PoCv6.52010-01-15
CVE-2010-0317 [HIGH] CWE-399 CVE-2010-0317: Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereferenc Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP requests that are not properly handled by (1) the CIFS functionality in CIFS.nlm Semantic Agent (Build 163 MP) 3.27 or (2) the AFP functionality in AFPTCP.nlm Build 163 SP 3.2
nvd
CVE-2005-2852P4MEDIUMCVSS 5.0PoCv5.1v6.0+1 more2005-09-08
CVE-2005-2852 [MEDIUM] CVE-2005-2852: Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote atta Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a denial of service (ABEND) via an incorrect password length, as exploited by the "worm.rbot.ccc" worm.
nvd
CVE-1999-1020P4HIGHCVSS 7.5PoCv4.1v4.111998-09-18
CVE-1999-1020 [HIGH] CVE-1999-1020: The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.
nvd
CVE-2004-2104P4MEDIUMCVSS 5.0PoCv5.1v6.02004-12-31
CVE-2004-2104 [MEDIUM] CVE-2004-2104: Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.
nvd
CVE-2000-0257P4HIGHCVSS 7.5PoCv5.12000-04-19
CVE-2000-0257 [HIGH] CVE-2000-0257: Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.
nvd
CVE-2008-5696P3CRITICALCVSS 9.3≤ 6.5v6.52008-12-19
CVE-2008-5696 [CRITICAL] CWE-255 CVE-2008-5696: Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.
nvd
CVE-2002-1634P4MEDIUMCVSS 5.0PoCv5.0v5.12002-12-31
CVE-2002-1634 [MEDIUM] CVE-2002-1634: Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive info Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3) websinfo.bas, (4) ndslogin.pl, (5) volscgi.pl, (6) lancgi.pl, (7) test.jse, or (8) env.pl.
nvd
CVE-2003-0562P4MEDIUMCVSS 5.0PoCv5.1v6.02003-08-27
CVE-2003-0562 [MEDIUM] CVE-2003-0562: Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attacke Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.
nvd
CVE-2003-1594P3HIGHCVSS 7.5v6.52010-04-05
CVE-2003-1594 [HIGH] CWE-264 CVE-2003-1594: NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly enforce FTPREST. NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly enforce FTPREST.TXT settings, which allows remote attackers to bypass intended access restrictions via an FTP session.
nvd
CVE-2003-1596P3HIGHCVSS 7.5v5.1v6.0+1 more2010-04-05
CVE-2003-1596 [HIGH] CWE-264 CVE-2003-1596: NWFTPD.nlm before 5.03.12 in the FTP server in Novell NetWare does not properly restrict filesystem NWFTPD.nlm before 5.03.12 in the FTP server in Novell NetWare does not properly restrict filesystem use by anonymous users with NFS Gateway home directories, which allows remote attackers to bypass intended access restrictions via an FTP session.
nvd
CVE-2003-1593P3HIGHCVSS 7.5v6.0v6.52010-04-05
CVE-2003-1593 [HIGH] CWE-264 CVE-2003-1593: NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 does not enforce do NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 does not enforce domain-name login restrictions, which allows remote attackers to bypass intended access control via an FTP connection.
nvd
CVE-2004-2734P3CRITICALCVSS 10.0v6.52004-12-31
CVE-2004-2734 [CRITICAL] CWE-287 CVE-2004-2734: webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.
nvd
CVE-1999-0470P4MEDIUMCVSS 5.0PoCv4.01999-04-09
CVE-1999-0470 [MEDIUM] CVE-1999-0470: A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily d A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.
nvd
CVE-2002-2096P3HIGHCVSS 7.5v5.1v6.02002-12-31
CVE-2002-2096 [HIGH] CVE-2002-2096: Buffer overflow in Novell Remote Manager module, httpstk.nlm, in NetWare 5.1 and NetWare 6 allows re Buffer overflow in Novell Remote Manager module, httpstk.nlm, in NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary code via a long (1) username or (2) password.
nvd
Novell Netware vulnerabilities | cvebase