CVEs (35)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Novell 1Zenworks Configuration Management Apr 29, 2026 Nov 2, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename pa...Show more |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Jun 17, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via...Show more |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Jun 17, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via...Show more |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Jun 17, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in a ZCC page in zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTM...Show more |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Jun 17, 2013 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to redirect u...Show more |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Mar 29, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory travers...Show more |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Mar 29, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers...Show more |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Jul 26, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Buffer overflow in the DoFindReplace function in the ISGrid.Grid2.1 ActiveX control in InstallShield/ISGrid2.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attac...Show more |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Jul 26, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The ISList.ISAvi ActiveX control in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 provides access to the mscomct2.ocx file, which allows remote attackers to execute arbitrary code b...Show more |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Jul 26, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 a...Show more |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Apr 11, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The xplat agent in Novell ZENworks Configuration Management (ZCM) 10.3.x before 10.3.4 and 11.x before 11.2 enables the HTTP TRACE method, which might make it easier for remote attackers to conduct cross-site tracing (XS...Show more |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Apr 9, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to read arbitrary files via an opcode 0x21 request. |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Apr 9, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x4c request. |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Apr 9, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x6c request. |
1Novell 1Zenworks Configuration Management Apr 29, 2026 Apr 18, 2011 N/A· v4 N/A· v3 10.0 HIGH· v2 Directory traversal vulnerability in an unspecified servlet in the Inventory component in ZENworks Asset Management (ZAM) in Novell ZENworks Configuration Management 10.3 before 10.3.2, and 11, allows remote attackers to...Show more |