cbcvebase.

Novell Netware vulnerabilities

63 known vulnerabilities affecting novell/netware.

Total CVEs
63
CISA KEV
0
Public exploits
14
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH15MEDIUM39LOW2

Vulnerabilities

Page 2 of 4
CVE-2000-0669P4MEDIUMCVSS 5.0PoCv5.02000-07-11
CVE-2000-0669 [MEDIUM] CVE-2000-0669: Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.
nvd
CVE-2002-1413P3HIGHCVSS 7.5v6.02003-04-11
CVE-2002-1413 [HIGH] CVE-2002-1413: RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypas RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection.
nvd
CVE-2010-0625P3MEDIUMCVSS 6.5v5.1v6.0+1 more2010-04-05
CVE-2010-0625 [MEDIUM] CWE-119 CVE-2010-0625: Stack-based buffer overflow in NWFTPD.nlm before 5.10.01 in the FTP server in Novell NetWare 5.1 thr Stack-based buffer overflow in NWFTPD.nlm before 5.10.01 in the FTP server in Novell NetWare 5.1 through 6.5 SP8 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long (1) MKD, (2) RMD, (3) RNFR, or (4) DELE command.
nvd
CVE-2003-1595P4CRITICALCVSS 10.0v6.52010-04-05
CVE-2003-1595 [CRITICAL] CWE-264 CVE-2003-1595: NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly perform "intrude NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly perform "intruder detection," which has unspecified impact and attack vectors.
nvd
CVE-2000-1245P4HIGHCVSS 7.5v5.12010-04-05
CVE-2000-1245 [HIGH] CWE-264 CVE-2000-1245: Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors.
nvd
CVE-1999-1086P4CRITICALCVSS 10.0≤ 5.0v4.1+1 more1999-07-15
CVE-1999-1086 [CRITICAL] CVE-1999-1086: Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls.
nvd
CVE-2006-2327P4MEDIUMCVSS 6.4v6.52006-05-12
CVE-2006-2327 [MEDIUM] CWE-189 CVE-2006-2327: Multiple integer overflows in the DPRPC library (DPRPCNLM.NLM) NDPS/iPrint module in Novell Distribu Multiple integer overflows in the DPRPC library (DPRPCNLM.NLM) NDPS/iPrint module in Novell Distributed Print Services in Novell NetWare 6.5 SP3, SP4, and SP5 allow remote attackers to execute arbitrary code via an XDR encoded array with a field that specifies a large number of elements, which triggers the overflows in the ndps_xdr_array function.
nvd
CVE-2002-1437P4MEDIUMCVSS 5.0v5.1v6.02003-04-11
CVE-2002-1437 [MEDIUM] CVE-2002-1437: Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWar Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.
nvd
CVE-2002-1417P4MEDIUMCVSS 5.0v5.1v6.02003-04-11
CVE-2002-1417 [MEDIUM] CVE-2002-1417: Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, a Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL containing a "..%5c" sequence (modified dot-dot), which is mapped to the directory separator.
nvd
CVE-2005-4887P4HIGHCVSS 7.5v6.52010-04-05
CVE-2005-4887 [HIGH] CVE-2005-4887: NWFTPD.nlm before 5.06.05 in the FTP server in Novell NetWare 6.5 SP5 allows attackers to have an un NWFTPD.nlm before 5.06.05 in the FTP server in Novell NetWare 6.5 SP5 allows attackers to have an unspecified impact via vectors related to passwords.
nvd
CVE-2003-1150P4HIGHCVSS 7.5v6.02003-10-27
CVE-2003-1150 [HIGH] CVE-2003-1150: Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Deskto Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors.
nvd
CVE-2000-0600P4HIGHCVSS 7.5v5.0v5.12000-06-26
CVE-2000-0600 [HIGH] CVE-2000-0600: Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or ex Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL.
nvd
CVE-2003-0976P4HIGHCVSS 7.5v6.52003-12-15
CVE-2003-0976 [HIGH] CVE-2003-0976: NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostnam NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount file systems when XNFS should deny the host.
nvd
CVE-2005-0819P4MEDIUMCVSS 5.0v6.52005-05-02
CVE-2005-0819 [MEDIUM] CVE-2005-0819: The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession wi The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start.
nvd
CVE-2004-2105P4MEDIUMCVSS 5.0v5.1v6.02004-12-31
CVE-2004-2105 [MEDIUM] CVE-2004-2105: The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to re The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt files via a full pathname in the error parameter.
nvd
CVE-2003-1592P4MEDIUMCVSS 5.0v6.0v6.52010-04-05
CVE-2003-1592 [MEDIUM] CWE-119 CVE-2003-1592: Multiple buffer overflows in NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 b Multiple buffer overflows in NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allow remote attackers to cause a denial of service (abend) via a long (1) username or (2) password.
nvd
CVE-2002-2434P4MEDIUMCVSS 5.0v5.1v6.0+1 more2010-04-05
CVE-2002-2434 [MEDIUM] CVE-2002-2434: NWFTPD.nlm before 5.02i in the FTP server in Novell NetWare does not properly listen for data connec NWFTPD.nlm before 5.02i in the FTP server in Novell NetWare does not properly listen for data connections, which allows remote attackers to cause a denial of service (abend) via multiple FTP sessions.
nvd
CVE-2004-2106P4MEDIUMCVSS 5.0v5.1v6.02004-12-31
CVE-2004-2106 [MEDIUM] CVE-2004-2106: Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a d Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3) /com/novell/webaccess, or (4) /ns-icons/.
nvd
CVE-2006-6675P4MEDIUMCVSS 6.8v6.52006-12-21
CVE-2006-6675 [MEDIUM] CVE-2006-6675: Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apach Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in Welcome web-app.
nvd
CVE-2006-1322P4MEDIUMCVSS 5.0v6.52006-03-20
CVE-2006-1322 [MEDIUM] CVE-2006-1322: Novell Netware NWFTPD 5.06.05 allows remote attackers to cause a denial of service (ABEND) via an MD Novell Netware NWFTPD 5.06.05 allows remote attackers to cause a denial of service (ABEND) via an MDTM command that uses a long path for the target file, possibly due to a buffer overflow.
nvd