Open Enterprise Server

Vendor:

First CVE: Aug 5, 2005 · Active for 20 years

20
Total CVEs
More Total CVEs than 95% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
10.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Open Enterprise Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 5, 2005
20 years ago
Most Recent CVE
Dec 30, 2019
2,402 days ago

CVE Severity & Scoring

Open Enterprise Server20 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local2 (10.0%)
Network3 (15.0%)
Unknown15 (75.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (25.0%)
High0 (0.0%)
Unknown15 (75.0%)
User Interaction
None5 (25.0%)
Unknown15 (75.0%)
Required0 (0.0%)
Privileges Required
Low2 (10.0%)
High0 (0.0%)
None3 (15.0%)
Unknown15 (75.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small size
Dec 30, 20197.832NONO
Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary
Feb 27, 200610.027NONO
Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintenance Update 9413 for Linux has u
Aug 17, 201410.025NONO
Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified impact and remote attack vectors.
Jun 18, 201410.025NONO
Buffer overflow in Novell iPrint Server in Novell Open Enterprise Server 2 (OES2) through SP3 on Linux allows remote attackers to execute arbitrary code via a crafted attributes-na
Feb 2, 20127.525NONO
nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial
Nov 13, 20089.325NONO
Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary w
Feb 17, 20094.323NOYES
Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (novell-nrm) in Novell SUSE Linux Enterprise Server 9 allows remote attackers to execute arbitrary code v
Dec 31, 20057.521NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
2 CVEs
10.0% of CVEs· 98th percentile
Metasploit
1 CVE
5.0% of CVEs· 97th percentile
Nuclei
1 CVE
5.0% of CVEs· 97th percentile
ExploitDB
3 CVEs
15.0% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Open Enterprise Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
933.92.2%00
2.0.317.53.0%00
2.0.217.53.0%00
201517.53.2%00
2.0.117.53.0%00
2.039.067.7%22
217.53.0%00
1.x14.32.2%01
11.097.319.6%22
1110.06.9%00