← Back

Novell

novell

657 CVEs • 111 products

Products (111)

Click to collapse
Toggle
Groupwise
groupwise
Netware
netware
Edirectory
edirectory
Iprint
iprint
Suse Linux
suse_linux
Netmail
netmail
Client
client
Imanager
imanager
Ichain
ichain
Bordermanager
bordermanager
Linux Desktop
linux_desktop
File Reporter
file_reporter
Mobility Pack
mobility_pack
Zenworks
zenworks
Suse Manager
suse_manager
Filr
filr
Iprint Client
iprint_client
Moonlight
moonlight
Leap
leap
Service Desk
service_desk
Web Server
web_server
Netmail Xe
netmail_xe
Emframe
emframe
Securelogin
securelogin
Teaming
teaming
Vibe Onprem
vibe_onprem
Messenger
messenger
Suse Cloud
suse_cloud
Web Search
web_search
Nsure Audit
nsure_audit
Imonitor
imonitor
Opensuse Swamp
opensuse_swamp
Apparmor
apparmor
Novell Forum
novell_forum
Cloud Manager
cloud_manager
Unixware
unixware
Kanaka
kanaka
Libzypp
libzypp

CVEs (657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
LinuxNovell
10Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 more
May 6, 2026
Apr 27, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of I...Show more
The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses.Show less
2Linux
Novell
9Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+6 more
May 6, 2026
Apr 27, 2016
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted en...Show more
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.Show less
2Linux
Novell
9Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+6 more
May 6, 2026
Apr 27, 2016
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLA...Show more
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.Show less
2Linux
Novell
9Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+6 more
May 6, 2026
Apr 27, 2016
N/A· v4
6.2 MEDIUM· v3
4.9 MEDIUM· v2
fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes.
2Linux
Novell
2Linux Kernel
Suse Linux Enterprise Real Time Extension
May 6, 2026
Apr 27, 2016
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified othe...Show more
Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an invalid USB descriptor.Show less
3Canonical
LinuxNovell
10Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 more
May 6, 2026
Apr 27, 2016
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or do...Show more
The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via a crafted endpoints value in a USB device descriptor.Show less
3Linux
NovellSuse
8Linux Kernel
Suse Linux Enterprise DesktopSuse Linux Enterprise Live Patching+5 more
May 6, 2026
Apr 27, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows loc...Show more
The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.Show less
3Linux
NovellSuse
11Linux Enterprise Live Patching
Linux Enterprise ServerLinux Kernel+8 more
May 6, 2026
Apr 27, 2016
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (in...Show more
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.Show less
3Canonical
LinuxNovell
3Linux Kernel
Suse Linux Enterprise Real Time ExtensionUbuntu Linux
May 6, 2026
Apr 27, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via...Show more
drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.Show less
2Linux
Novell
3Linux Kernel
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Real Time Extension
May 6, 2026
Apr 27, 2016
N/A· v4
6.2 MEDIUM· v3
4.9 MEDIUM· v2
Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening...Show more
Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.Show less
1Novell
1Service Desk
May 6, 2026
Apr 22, 2016
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstNa...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4) ta_selectedTopicContent, (5) tf_orgUnitName, (6) tf_aManufacturerFullName, (7) tf_aManufacturerName, (8) tf_aManufacturerAddress, or (9) tf_aManufacturerCity parameter.Show less
1Novell
1Service Desk
May 6, 2026
Apr 22, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensi...Show more
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.Show less
1Novell
1Service Desk
May 6, 2026
Apr 22, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFile...Show more
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.Show less
1Novell
1Service Desk
May 6, 2026
Apr 22, 2016
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a fil...Show more
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.Show less
4Debian
GoogleNovell+1 more
4Chrome
Debian LinuxLeap+1 more
May 6, 2026
Apr 18, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive infor...Show more
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.Show less
4Debian
GoogleNovell+1 more
4Chrome
Debian LinuxLeap+1 more
May 6, 2026
Apr 18, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attack...Show more
The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.Show less
2Novell
Xen
2Suse Linux Enterprise Real Time Extension
Xen
May 6, 2026
Apr 14, 2016
N/A· v4
8.2 HIGH· v3
5.7 MEDIUM· v2
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a d...Show more
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.Show less
4Canonical
DebianNovell+1 more
5Debian Linux
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Real Time Extension+2 more
May 6, 2026
Apr 13, 2016
N/A· v4
4.4 MEDIUM· v3
1.7 LOW· v2
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial...Show more
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and XEN_PCI_OP_enable_msi operations, aka "Linux pciback missing sanity checks."Show less
1Novell
1Filr
May 6, 2026
Mar 18, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Novell Filr 1.2 before Hot Patch 4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
4Mozilla
NovellOpensuse+1 more
6Firefox
LeapLinux+3 more
May 6, 2026
Mar 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation...Show more
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.Show less