VendorsNovellnetwareall versions
Vulnerabilities

Novell NetWare

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

76CVEs
CVE-2002-1418
Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to cause a denial of service (ABEND) via a long module name.
Published 2004-09-01 · Modified
5.0EPSS 0.027
CVE-2000-0669
Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.
Published 2000-10-13 · Modified
5.01 PoCEPSS 0.025
CVE-2005-0819
The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start.
Published 2005-03-20 · Modified
5.0EPSS 0.025
CVE-2005-1060
Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets.
Published 2005-04-12 · Modified
5.0EPSS 0.025
CVE-2002-1438
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option.
Published 2004-09-01 · Modified
5.0EPSS 0.024
CVE-2004-2106
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3) /com/novell/webaccess, or (4) /ns-icons/.
Published 2005-05-27 · Modified
5.0EPSS 0.023
CVE-2006-0999
The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) allows a client to force the server to use weak encryption by stating that a weak cipher is required for client compatibility, which might allow remote attackers to decrypt contents of an SSL protected session.
Published 2006-03-23 · Modified
5.0EPSS 0.023
CVE-2004-2336
Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.
Published 2005-08-16 · Modified
5.0EPSS 0.022
CVE-1999-0929
Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.
Published 2000-02-04 · Modified
5.0EPSS 0.019
CVE-2004-2105
The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt files via a full pathname in the error parameter.
Published 2005-05-27 · Modified
5.0EPSS 0.019
CVE-2002-0929
Buffer overflows in the DHCP server for NetWare 6.0 SP1 allow remote attackers to cause a denial of service (reboot) via long DHCP requests.
Published 2002-08-31 · Modified
5.0EPSS 0.019
CVE-2003-1592
Multiple buffer overflows in NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allow remote attackers to cause a denial of service (abend) via a long (1) username or (2) password.
Published 2010-04-05 · Modified
5.0EPSS 0.017
CVE-2002-2434
NWFTPD.nlm before 5.02i in the FTP server in Novell NetWare does not properly listen for data connections, which allows remote attackers to cause a denial of service (abend) via multiple FTP sessions.
Published 2010-04-05 · Modified
5.0EPSS 0.017
CVE-2002-2432
Unspecified vulnerability in NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via a crafted username.
Published 2010-04-05 · Modified
5.0EPSS 0.017
CVE-2005-4888
NWFTPD.nlm before 5.06.04 in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (excessive stale connections) by establishing many FTP sessions, which persist in the Not-Logged-In state after each session is completed.
Published 2010-04-05 · Modified
5.0EPSS 0.017
CVE-2002-0930
Format string vulnerability in the FTP server for Novell Netware 6.0 SP1 (NWFTPD) allows remote attackers to cause a denial of service (ABEND) via format strings in the USER command.
Published 2002-08-31 · Modified
5.0EPSS 0.017
CVE-2002-0791
Novell Netware FTP server NWFTPD before 5.02r allows remote attackers to cause a denial of service (CPU consumption) via a connection to the server followed by a carriage return, and possibly other invalid commands with improper syntax or length.
Published 2002-07-26 · Modified
5.0EPSS 0.017
CVE-2001-1233
Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.
Published 2002-05-03 · Modified
5.0EPSS 0.016
CVE-2006-0997
The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic.
Published 2006-03-23 · Modified
5.0EPSS 0.016
CVE-1999-0805
Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests.
Published 2001-02-14 · Modified
5.0EPSS 0.013
CVE-2001-1587
NWFTPD.nlm before 5.01w in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via an anonymous STOU command.
Published 2010-04-05 · Modified
5.0EPSS 0.011
CVE-1999-0265
ICMP redirect messages may crash or lock up a host.
Published 1999-09-29 · Modified
5.0EPSS 0.011
CVE-2002-1772
Novell Netware 5.0 through 5.1 may allow local users to gain "Domain Admin" rights by logging into a Novell Directory Services (NDS) account, and executing "net use" on an NDS_ADM account that is not in the NT domain but has domain access rights, which allows the user to enter a null password.
Published 2005-06-21 · Modified
4.6EPSS 0.004
CVE-1999-1215
LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges.
Published 2002-03-09 · Modified
4.6EPSS 0.004
CVE-1999-1320
Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing.
Published 2002-03-09 · Modified
4.6EPSS 0.003
CVE-2004-2103
Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version parameter to webacc, or (4) a URL request for a .bas file with script in the filename.
Published 2005-05-27 · Modified
4.3EPSS 0.021
CVE-2003-1591
NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allows user-assisted remote attackers to cause a denial of service (console hang) via a large number of FTP sessions, which are not properly handled during an NLM unload.
Published 2010-04-05 · Modified
4.3EPSS 0.015
CVE-2004-2767
NWFTPD.nlm before 5.04.25 in the FTP server in Novell NetWare does not promptly close DS sessions, which allows remote attackers to cause a denial of service (connection slot exhaustion) by establishing many FTP sessions that persist for the lifetime of a DS session.
Published 2010-04-05 · Modified
4.3EPSS 0.015
CVE-2007-3571
The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.
Published 2007-07-05 · Modified
4.3EPSS 0.012
CVE-1999-0524
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
Published 2000-02-04 · Modified
4.0EPSS 0.322
CVE-2006-2185
PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password in cleartext to the abend.log log file when the groupOperationsMethod function fails, which allows context-dependent attackers to gain privileges.
Published 2006-05-22 · Modified
4.0EPSS 0.016
CVE-2007-6734
NWFTPD.nlm before 5.08.07 in the FTP server in Novell NetWare 6.5 SP7 does not properly implement the FTPREST.TXT NOREMOTE restriction, which allows remote authenticated users to access directories outside of the home server via unspecified vectors.
Published 2010-04-05 · Modified
4.0EPSS 0.014
CVE-2002-2433
NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote authenticated users to cause a denial of service (abend) via a crafted ABOR command.
Published 2010-04-05 · Modified
4.0EPSS 0.014
CVE-2000-1246
NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allows remote authenticated users to cause a denial of service (abend) by sending an RNTO command after a failed RNFR command.
Published 2010-04-05 · Modified
3.5EPSS 0.008
CVE-2004-2414
Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.
Published 2005-08-18 · Modified
2.1EPSS 0.004
CVE-2002-2083
The Novell Netware client running on Windows 95 allows local users to bypass the login and open arbitrary files via the "What is this?" help feature, which can be launched from the Novell Netware login screen.
Published 2005-07-14 · Modified
2.1EPSS 0.004
← Prev2 / 2