← Back

Novell

novell

657 CVEs • 111 products

Products (111)

Click to collapse
Toggle
Groupwise
groupwise
Netware
netware
Edirectory
edirectory
Iprint
iprint
Suse Linux
suse_linux
Netmail
netmail
Client
client
Imanager
imanager
Ichain
ichain
Bordermanager
bordermanager
Linux Desktop
linux_desktop
File Reporter
file_reporter
Mobility Pack
mobility_pack
Zenworks
zenworks
Suse Manager
suse_manager
Filr
filr
Iprint Client
iprint_client
Moonlight
moonlight
Leap
leap
Service Desk
service_desk
Web Server
web_server
Netmail Xe
netmail_xe
Emframe
emframe
Securelogin
securelogin
Teaming
teaming
Vibe Onprem
vibe_onprem
Messenger
messenger
Suse Cloud
suse_cloud
Web Search
web_search
Nsure Audit
nsure_audit
Imonitor
imonitor
Opensuse Swamp
opensuse_swamp
Apparmor
apparmor
Novell Forum
novell_forum
Cloud Manager
cloud_manager
Unixware
unixware
Kanaka
kanaka
Libzypp
libzypp

CVEs (657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Linux
Novell
2Linux Kernel
Suse Linux Enterprise Server
May 6, 2026
Sep 28, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system c...Show more
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.Show less
17Apple
AristaCanonical+14 more
74Arx Firmware
BashBig Ip Access Policy Manager+71 more
Apr 22, 2026
Sep 25, 2014
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth...Show more
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.Show less
17Apple
AristaCanonical+14 more
74Arx Firmware
BashBig Ip Access Policy Manager+71 more
Apr 22, 2026
Sep 24, 2014
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec...Show more
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.Show less
1Novell
1Groupwise
May 6, 2026
Sep 5, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecifie...Show more
The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.Show less
1Novell
1Groupwise
May 6, 2026
Aug 29, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.
1Novell
1Open Enterprise Server
May 6, 2026
Aug 17, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintenance Update 9413 for Linux has unknown impact and attack vectors.
1Novell
1Open Enterprise Server
May 6, 2026
Jun 18, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vect...Show more
Cross-site scripting (XSS) vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Novell
1Open Enterprise Server
May 6, 2026
Jun 18, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified impact and remote attack vectors.
1Novell
1Open Enterprise Server
May 6, 2026
May 8, 2014
N/A· v4
N/A· v3
2.6 LOW· v2
/opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic c...Show more
/opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic circumstances by leveraging the granting of the F permission by an administrator.Show less
1Novell
1Suse Lifecycle Management Server
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.
2Crowbar
Novell
2Barclamp
Suse Cloud
May 6, 2026
Apr 4, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass security group restriction...Show more
Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass security group restrictions via unspecified vectors, related to floating IPs.Show less
7Canonical
DebianMozilla+4 more
16Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+13 more
May 6, 2026
Mar 19, 2014
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation informat...Show more
The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing attack involving feDisplacementMap elements, a related issue to CVE-2013-1693.Show less
1Novell
1Zenworks Configuration Management
May 6, 2026
Mar 6, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN...Show more
Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595.Show less
1Novell
1Identity Manager Roles Based Provisioning Module
Apr 29, 2026
Dec 28, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDe...Show more
Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId.Show less
2Novell
Suse
3Studio Onsite
Suse Lifecycle Management ServerWebyast
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
7.2 HIGH· v2
WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.
1Novell
1Client
Apr 29, 2026
Dec 22, 2013
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The VBA32 AntiRootKit component for Novell Client 2 SP3 before IR5 on Windows allows local users to cause a denial of service (bugcheck and BSOD) via an IOCTL call for an invalid IOCTL.
1Novell
1Suse Lifecycle Management Server
Apr 29, 2026
Dec 10, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
SUSE Lifecycle Management Server (SLMS) before 1.3.7 uses world-readable permissions for the secret keys, which allows local users to gain privileges via unspecified vectors.
1Novell
1Suse Lifecycle Management Server
Apr 29, 2026
Dec 10, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledg...Show more
SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of this key from a product installation elsewhere.Show less
1Novell
1Suse Cloud
Apr 29, 2026
Dec 2, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecified impact and attack vectors.
1Novell
1Suse Linux Enterprise For Sap Applications
Apr 29, 2026
Dec 2, 2013
N/A· v4
N/A· v3
7.2 HIGH· v2
Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an unspecified impact via vectors related to a tmp/ directory.