Novell
novell
657 CVEs • 111 products
Products (111)
Click to collapseToggle
Products (111)
Click to collapse
CVEs (657)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Novell 1Zenworks Configuration Management May 13, 2026 Aug 9, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders via the dirname variable. |
1Novell 1Zenworks Configuration Management May 13, 2026 Aug 9, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLogins for the maintenance variable. |
1Novell 1Zenworks Configuration Management May 13, 2026 Aug 9, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename variable. |
1Novell 1Zenworks Configuration Management May 13, 2026 Aug 9, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |
1Novell 1Zenworks Configuration Management May 13, 2026 Aug 9, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors. |
1Novell 1Zenworks Configuration Management May 13, 2026 Aug 9, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |
10Canonical DebianFedoraproject+7 more18Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+15 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a craft...Show more |
4Fedoraproject GolangNovell+1 more4Fedora GoLeap+1 moreMay 13, 2026 Jul 6, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive att...Show more |
8Debian GnuMcafee+5 more20Cloud Magnum Orchestration Debian LinuxEnterprise Linux+17 moreMay 13, 2026 Jun 19, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hard...Show more |
5Fedoraproject Game Music Emu ProjectNovell+2 more7Fedora Game Music EmuLeap+4 moreMay 13, 2026 Jun 6, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 game-music-emu before 0.6.1 mishandles unspecified integer values. |
5Fedoraproject Game Music Emu ProjectNovell+2 more7Fedora Game Music EmuLeap+4 moreMay 13, 2026 Jun 6, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash). |
3Novell SuseXen6Manager Manager ProxyOpenstack Cloud+3 moreMay 13, 2026 May 3, 2017 N/A· v4 3.8 LOW· v3 1.7 LOW· v2 Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function....Show more |
2Netiq Novell2Imanager ImanagerMay 13, 2026 May 3, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability. |
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management. |
2Netiq Novell2Imanager ImanagerMay 13, 2026 May 3, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework. |
2Netiq Novell4Edirectory EdirectoryImanager+1 moreMay 13, 2026 Apr 27, 2017 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing...Show more |
Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a hea...Show more |
Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email. |
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) tok...Show more |
A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScript in the context of...Show more |