← Back

Novell

novell

657 CVEs • 111 products

Products (111)

Click to collapse
Toggle
Groupwise
groupwise
Netware
netware
Edirectory
edirectory
Iprint
iprint
Suse Linux
suse_linux
Netmail
netmail
Client
client
Imanager
imanager
Ichain
ichain
Bordermanager
bordermanager
Linux Desktop
linux_desktop
File Reporter
file_reporter
Mobility Pack
mobility_pack
Zenworks
zenworks
Suse Manager
suse_manager
Filr
filr
Iprint Client
iprint_client
Moonlight
moonlight
Leap
leap
Service Desk
service_desk
Web Server
web_server
Netmail Xe
netmail_xe
Emframe
emframe
Securelogin
securelogin
Teaming
teaming
Vibe Onprem
vibe_onprem
Messenger
messenger
Suse Cloud
suse_cloud
Web Search
web_search
Nsure Audit
nsure_audit
Imonitor
imonitor
Opensuse Swamp
opensuse_swamp
Apparmor
apparmor
Novell Forum
novell_forum
Cloud Manager
cloud_manager
Unixware
unixware
Kanaka
kanaka
Libzypp
libzypp

CVEs (657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Novell
1Zenworks Desktop Management
Apr 29, 2026
May 5, 2013
N/A· v4
N/A· v3
7.2 HIGH· v2
Multiple unquoted Windows search path vulnerabilities in Novell ZENworks Desktop Management (ZDM) 7 through 7.1 might allow local users to gain privileges via a Trojan horse "program" file in the C: folder, related to an...Show more
Multiple unquoted Windows search path vulnerabilities in Novell ZENworks Desktop Management (ZDM) 7 through 7.1 might allow local users to gain privileges via a Trojan horse "program" file in the C: folder, related to an attempted launch of (1) ZenRem32.exe or (2) wm.exe.Show less
1Novell
1Iprint
Apr 29, 2026
May 2, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute arbitrary code via unspecified vectors.
1Novell
1Imanager
Apr 29, 2026
Apr 24, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
1Novell
1Imanager
Apr 29, 2026
Apr 24, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code...Show more
Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.Show less
1Novell
1Groupwise
Apr 29, 2026
Apr 19, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError attribute.
3Adobe
NovellOpensuse
5Adobe Air
Adobe Air SdkFlash Player+2 more
Apr 29, 2026
Apr 10, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on A...Show more
Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 do not properly initialize pointer arrays, which allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.Show less
1Novell
1Kanaka
Apr 29, 2026
Apr 7, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The installation functionality in the Novell Kanaka component before 2.8 for Novell Open Enterprise Server (OES) on Mac OS X does not verify the server's X.509 certificate during an SSL session, which allows man-in-the-m...Show more
The installation functionality in the Novell Kanaka component before 2.8 for Novell Open Enterprise Server (OES) on Mac OS X does not verify the server's X.509 certificate during an SSL session, which allows man-in-the-middle attackers to spoof servers via an arbitrary certificate.Show less
1Novell
2Groupwise Messenger
Messenger
Apr 29, 2026
Mar 29, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earlier, and Novell Messenger 2.1.x and 2.2.x before 2.2.2, allows remote attackers to execute arbitrary code via an import...Show more
Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earlier, and Novell Messenger 2.1.x and 2.2.x before 2.2.2, allows remote attackers to execute arbitrary code via an import command containing a long string in the filename parameter.Show less
1Novell
1Identity Manager Roles Based Provisioning Module
Apr 29, 2026
Mar 29, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the login functionality in the Reporting Module in Novell Identity Manager (aka IDM) Roles Based Provisioning Module 4.0.2 before Field Patch C has unknown impact and attack vectors.
1Novell
1Zenworks Mobile Management
Apr 29, 2026
Mar 29, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in DUSAP.php in Novell ZENworks Mobile Management before 2.7.1 allows remote attackers to include and execute arbitrary local files via the language parameter.
1Novell
1Zenworks Configuration Management
Apr 29, 2026
Mar 29, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory travers...Show more
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently upload and execute arbitrary programs, via a request to TCP port 443.Show less
1Novell
1Zenworks Configuration Management
Apr 29, 2026
Mar 29, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers...Show more
Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers to execute arbitrary local DLL files via a crafted web page that also calls the Initialize method.Show less
1Novell
1Sentinel Log Manager
Apr 29, 2026
Mar 29, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report...Show more
Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results "Save Query As" "Save As Retention Policy" action.Show less
1Novell
1Zenworks Mobile Management
Apr 29, 2026
Mar 11, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote attackers to include and execute arbitrary local files via the language parameter.
1Novell
1Groupwise
Apr 29, 2026
Feb 24, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via unspecified vectors.
1Novell
1Groupwise
Apr 29, 2026
Feb 24, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2)...Show more
An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method.Show less
1Novell
1Iprint
Apr 29, 2026
Dec 24, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Novell iPrint Client before 5.82 allows remote attackers to execute arbitrary code via an op-client-interface-version action.
1Novell
1File Reporter
Apr 29, 2026
Nov 18, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.
1Novell
1File Reporter
Apr 29, 2026
Nov 18, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.
1Novell
1File Reporter
Apr 29, 2026
Nov 18, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record.