Novell
novell
657 CVEs • 111 products
Products (111)
Click to collapseToggle
Products (111)
Click to collapse
CVEs (657)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-...Show more |
1Novell 2Identity Manager Roles Based Provisioning Module Identity Manager User ApplicationApr 29, 2026 Oct 8, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4...Show more |
Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file. |
Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a craft...Show more |
The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect...Show more |
2Marcus Schafer Novell2Kiwi Suse Studio OnsiteApr 29, 2026 Aug 23, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted archive file list that is used in an o...Show more |
2Marcus Schafer Novell2Kiwi Suse Studio OnsiteApr 29, 2026 Aug 23, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 Unspecified vulnerability in the file browser in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename. |
2Marcus Schafer Novell2Kiwi Suse Studio OnsiteApr 29, 2026 Aug 23, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RP...Show more |
2Marcus Schafer Novell2Kiwi Suse Studio OnsiteApr 29, 2026 Aug 23, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call. |
2Marcus Schafer Novell2Kiwi Suse Studio OnsiteApr 29, 2026 Aug 23, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a filter in a modified file. |
2Marcus Schafer Novell2Kiwi Suse Studio OnsiteApr 29, 2026 Aug 23, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted archive name in the list of testdrive modified files. |
2Marcus Schafer Novell2Kiwi Suse Studio OnsiteApr 29, 2026 Aug 23, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename in the list of testdrive modified files. |
2Marcus Schafer Novell2Kiwi Suse Studio OnsiteApr 29, 2026 Aug 23, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename for a custom RPM. |
2Marcus Schafer Novell2Kiwi Suse Studio OnsiteApr 29, 2026 Aug 23, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info disp...Show more |
2Marcus Schafer Novell2Kiwi Suse Studio OnsiteApr 29, 2026 Aug 23, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listin...Show more |
2Marcus Schafer Novell2Kiwi Suse Studio OnsiteApr 29, 2026 Aug 23, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to have an unknown impact via a crafted directory pathname that is inserted into config.sh. |
1Novell 2Data Synchronizer Mobility PackApr 29, 2026 Aug 9, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not properly restrict caching of HTTPS responses, which makes it easier for remote attackers to obtain sensitive information by le...Show more |
1Novell 2Data Synchronizer Mobility PackApr 29, 2026 Aug 9, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for remote attackers to obtain access via a brute-force attack. |
1Novell 2Data Synchronizer Mobility PackApr 29, 2026 Aug 9, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (...Show more |
1Novell 2Data Synchronizer Mobility PackApr 29, 2026 Aug 9, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network. |