← Back

Novell

novell

657 CVEs • 111 products

Products (111)

Click to collapse
Toggle
Groupwise
groupwise
Netware
netware
Edirectory
edirectory
Iprint
iprint
Suse Linux
suse_linux
Netmail
netmail
Client
client
Imanager
imanager
Ichain
ichain
Bordermanager
bordermanager
Linux Desktop
linux_desktop
File Reporter
file_reporter
Mobility Pack
mobility_pack
Zenworks
zenworks
Suse Manager
suse_manager
Filr
filr
Iprint Client
iprint_client
Moonlight
moonlight
Leap
leap
Service Desk
service_desk
Web Server
web_server
Netmail Xe
netmail_xe
Emframe
emframe
Securelogin
securelogin
Teaming
teaming
Vibe Onprem
vibe_onprem
Messenger
messenger
Suse Cloud
suse_cloud
Web Search
web_search
Nsure Audit
nsure_audit
Imonitor
imonitor
Opensuse Swamp
opensuse_swamp
Apparmor
apparmor
Novell Forum
novell_forum
Cloud Manager
cloud_manager
Unixware
unixware
Kanaka
kanaka
Libzypp
libzypp

CVEs (657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Novell
1Groupwise
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-...Show more
Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2219.Show less
1Novell
2Identity Manager Roles Based Provisioning Module
Identity Manager User Application
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4...Show more
Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 692972.Show less
1Novell
1Groupwise
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file.
1Novell
1Groupwise
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a craft...Show more
Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted TZNAME variable in a VCALENDAR attachment in an e-mail message, related to an "integer truncation error."Show less
1Novell
1Cloud Manager
Apr 29, 2026
Sep 6, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect...Show more
The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect privileges associated with a partially initialized session.Show less
2Marcus Schafer
Novell
2Kiwi
Suse Studio Onsite
Apr 29, 2026
Aug 23, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted archive file list that is used in an o...Show more
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted archive file list that is used in an overlay file.Show less
2Marcus Schafer
Novell
2Kiwi
Suse Studio Onsite
Apr 29, 2026
Aug 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in the file browser in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename.
2Marcus Schafer
Novell
2Kiwi
Suse Studio Onsite
Apr 29, 2026
Aug 23, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RP...Show more
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RPM info display.Show less
2Marcus Schafer
Novell
2Kiwi
Suse Studio Onsite
Apr 29, 2026
Aug 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.
2Marcus Schafer
Novell
2Kiwi
Suse Studio Onsite
Apr 29, 2026
Aug 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a filter in a modified file.
2Marcus Schafer
Novell
2Kiwi
Suse Studio Onsite
Apr 29, 2026
Aug 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted archive name in the list of testdrive modified files.
2Marcus Schafer
Novell
2Kiwi
Suse Studio Onsite
Apr 29, 2026
Aug 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename in the list of testdrive modified files.
2Marcus Schafer
Novell
2Kiwi
Suse Studio Onsite
Apr 29, 2026
Aug 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename for a custom RPM.
2Marcus Schafer
Novell
2Kiwi
Suse Studio Onsite
Apr 29, 2026
Aug 23, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info disp...Show more
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display.Show less
2Marcus Schafer
Novell
2Kiwi
Suse Studio Onsite
Apr 29, 2026
Aug 23, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listin...Show more
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listing.Show less
2Marcus Schafer
Novell
2Kiwi
Suse Studio Onsite
Apr 29, 2026
Aug 23, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to have an unknown impact via a crafted directory pathname that is inserted into config.sh.
1Novell
2Data Synchronizer
Mobility Pack
Apr 29, 2026
Aug 9, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not properly restrict caching of HTTPS responses, which makes it easier for remote attackers to obtain sensitive information by le...Show more
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not properly restrict caching of HTTPS responses, which makes it easier for remote attackers to obtain sensitive information by leveraging an unattended workstation.Show less
1Novell
2Data Synchronizer
Mobility Pack
Apr 29, 2026
Aug 9, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for remote attackers to obtain access via a brute-force attack.
1Novell
2Data Synchronizer
Mobility Pack
Apr 29, 2026
Aug 9, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (...Show more
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.Show less
1Novell
2Data Synchronizer
Mobility Pack
Apr 29, 2026
Aug 9, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.