Novell
novell
657 CVEs • 111 products
Products (111)
Click to collapseToggle
Products (111)
Click to collapse
CVEs (657)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking. |
NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtere...Show more |
A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies. |
1Novell 1Netiq Idm Servicenow Driver May 13, 2026 Mar 23, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information leak in the NetIQ IDM ServiceNow Driver before 1.0.0.1 could expose cryptographic attributes to logged-in users. |
6Canonical ImagemagickNovell+3 more11Imagemagick LeapLeap+8 moreMay 13, 2026 Mar 17, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file. |
Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overflowing the "name" parameter. |
4Novell NtpOpensuse+1 more10Leap Linux Enterprise DebuginfoLinux Enterprise Desktop+7 moreMay 13, 2026 Jan 30, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename. |
Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that allows complete directory traversal and total information disclosure. T...Show more |
1Novell 2Open Enterprise Server 11 Open Enterprise Server 2015May 6, 2026 Nov 15, 2016 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10990, OES11 SP3 before Scheduled Maintenance Update 10991, OES11 SP2 bef...Show more |
1Novell 2Identity Manager Identity Manager Identity ApplicationsMay 6, 2026 Oct 27, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages. |
3Novell RedhatSystemd Project9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+6 moreMay 6, 2026 Oct 13, 2016 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notif...Show more |
3Nodejs NovellOpenssl3Node.js OpensslSuse Linux Enterprise Module For Web ScriptingMay 6, 2026 Sep 26, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation. |
6Canonical DebianHp+3 more9Debian Linux Icewall Federation AgentIcewall Mcrp+6 moreMay 6, 2026 Sep 26, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr....Show more |
3Nodejs NovellOpenssl3Node.js OpensslSuse Linux Enterprise Module For Web ScriptingMay 6, 2026 Sep 26, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions. |
4Debian EsNovell+1 more5Debian Linux Iperf3Leap+2 moreMay 6, 2026 Sep 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string,...Show more |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file. |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file. |
4Canonical LibarchiveNovell+1 more6Libarchive LinuxSuse Linux Enterprise Desktop+3 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to th...Show more |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file. |