CVE-2017-7430
- EPSS 0.66%
- Published 03.05.2017 05:59:00
- Last modified 20.04.2025 01:37:25
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
CVE-2017-7431
- EPSS 0.28%
- Published 03.05.2017 05:59:00
- Last modified 20.04.2025 01:37:25
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
CVE-2017-7432
- EPSS 1.09%
- Published 03.05.2017 05:59:00
- Last modified 20.04.2025 01:37:25
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.
CVE-2017-5186
- EPSS 0.47%
- Published 27.04.2017 14:59:00
- Last modified 20.04.2025 01:37:25
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications ...
CVE-2013-1088
- EPSS 0.59%
- Published 24.04.2013 10:28:37
- Last modified 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tom...
- EPSS 0.19%
- Published 24.04.2013 10:28:37
- Last modified 11.04.2025 00:51:21
Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
- EPSS 5.14%
- Published 09.04.2012 20:55:02
- Last modified 11.04.2025 00:51:21
Buffer overflow in the Create Attribute function in jclient in Novell iManager 2.7.4 before patch 4 allows remote authenticated users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted EnteredAttr...
- EPSS 19.47%
- Published 28.06.2010 17:30:01
- Last modified 11.04.2025 00:51:21
Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated users to execute arbitrary code...
- EPSS 28.46%
- Published 28.06.2010 17:30:01
- Last modified 11.04.2025 00:51:21
Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree parameter in a login request to nps/servlet/webacc.
CVE-2009-4486
- EPSS 7.6%
- Published 08.01.2010 18:30:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in the eDirectory plugin in Novell iManager before 2.7.3 allows remote attackers to execute arbitrary code via vectors that trigger long arguments to an unspecified sub-application, related to importing and exporting from ...