Novell / Ichain
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2004-2757 | Cross-site scripting (XSS) vulnerability in the failed login page in Novell iChain before 2.2 build 2.2.113 and 2.3 First Customer Ship (FCS) allows remote att… | MEDIUM | 4.3 | Nov 20, 2007 |
| CVE-2004-2582 | Novell iChain 2.3 includes the build number in the VIA line of the proxy server's HTTP headers, which allows remote attackers to obtain sensitive information. | MEDIUM | 5.0 | Nov 28, 2005 |
| CVE-2004-2581 | Novell iChain 2.3 allows attackers to cause a denial of service via a URL with a "specific string." | MEDIUM | 5.0 | Nov 28, 2005 |
| CVE-2004-2580 | Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via unspecified vectors. | MEDIUM | 5.8 | Nov 28, 2005 |
| CVE-2004-2579 | ACLCHECK module in Novell iChain 2.3 allows attackers to bypass access control rules of an unspecified component via an unspecified attack vector involving a s… | HIGH | 7.5 | Nov 28, 2005 |
| CVE-2004-2314 | The Telnet listener for Novell iChain Server before 2.2 Field Patch 3b 2.2.116 does not have a password by default, which allows remote attackers to gain acces… | HIGH | 7.5 | Aug 16, 2005 |
| CVE-2005-0798 | Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to… | HIGH | 7.5 | Mar 20, 2005 |
| CVE-2005-0746 | The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD comm… | MEDIUM | 5.0 | Mar 13, 2005 |
| CVE-2005-0744 | The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows attackers to hijack sessions and gain administrator privileges by (1) sniffing the connection on T… | HIGH | 10.0 | Mar 13, 2005 |
| CVE-2003-0639 | Unknown vulnerability in Novell iChain 2.2 before Support Pack 1 allows users to access restricted or secure pages without authentication. | MEDIUM | 5.0 | Aug 2, 2003 |
| CVE-2003-0638 | Multiple buffer overflows in Novell iChain 2.1 before Field Patch 3, and iChain 2.2 before Field Patch 1a, allow attackers to cause a denial of service (ABEND)… | HIGH | 7.5 | Aug 2, 2003 |
| CVE-2003-0637 | Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess u… | MEDIUM | 5.0 | Aug 2, 2003 |
| CVE-2003-0636 | Novell iChain 2.2 before Support Pack 1 does not properly verify that URL redirects match the DNS name of an accelerator, which allows attackers to redirect UR… | HIGH | 7.5 | Aug 2, 2003 |
| CVE-2003-0635 | Unknown vulnerability or vulnerabilities in Novell iChain 2.2 before Support Pack 1, with unknown impact, possibly related to unauthorized access to (1) NCPIP.… | MEDIUM | 5.0 | Aug 2, 2003 |
Showing 1 to 14 of 14 CVEs