Page 133 of 671 results (0.008 seconds)

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to "Read Only," which NetWare-NFS changes to a setuid root program. • http://marc.info/?l=bugtraq&m=88427711321769&w=2 http://marc.info/?l=bugtraq&m=90295697702474&w=2 http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551 http://www.iss.net/security_center/static/7246.php •

CVSS: 5.0EPSS: 4%CPEs: 3EXPL: 1

Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter. • https://www.exploit-db.com/exploits/19682 http://marc.info/?l=bugtraq&m=94571433731824&w=2 http://www.osvdb.org/3413 http://www.securityfocus.com/bid/879 •

CVSS: 5.0EPSS: 0%CPEs: 2EXPL: 0

Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter. • http://marc.info/?l=bugtraq&m=94571433731824&w=2 •

CVSS: 10.0EPSS: 0%CPEs: 3EXPL: 1

Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls. • http://marc.info/?l=bugtraq&m=93214475111651&w=2 http://www.securityfocus.com/bid/528 •

CVSS: 5.0EPSS: 0%CPEs: 4EXPL: 0

Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0929 •