Novell / Data Synchronizer
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2011-3014 | The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not properly restrict caching of HTTPS responses, which makes it easi… | MEDIUM | 5.0 | Aug 9, 2011 |
| CVE-2011-3013 | WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for remote at… | MEDIUM | 5.0 | Aug 9, 2011 |
| CVE-2011-2224 | The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it… | MEDIUM | 4.3 | Aug 9, 2011 |
| CVE-2011-2223 | The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers… | MEDIUM | 5.0 | Aug 9, 2011 |
| CVE-2011-2222 | Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to h… | MEDIUM | 4.3 | Aug 9, 2011 |
| CVE-2011-2221 | The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and obtain sensi… | MEDIUM | 5.0 | Aug 9, 2011 |
| CVE-2011-1711 | Unspecified vulnerability in the Mobility Pack 1.1.2 and earlier in Novell Data Synchronizer 1.0.x, and 1.1.x through 1.1.1 build 428, allows remote authentica… | MEDIUM | 5.5 | Jun 7, 2011 |
Showing 1 to 7 of 7 CVEs