Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · novell

novell

· 8 Critical

Total CVEs

675

Critical

8

Products

111

Search All CVEs →

675

Products (111)

suse linux enterprise server94 CVEssuse linux enterprise desktop83 CVEsnetware76 CVEsgroupwise75 CVEssuse linux enterprise software development kit65 CVEsedirectory52 CVEszenworks configuration management35 CVEssuse linux enterprise real time extension33 CVEsiprint30 CVEssuse linux enterprise workstation extension24 CVEssuse linux enterprise debuginfo24 CVEssuse linux23 CVEsopen enterprise server22 CVEssuse linux enterprise module for public cloud22 CVEssuse linux enterprise live patching22 CVEsnetmail17 CVEssuse package hub for suse linux enterprise17 CVEsnetware ftp server17 CVEsimanager16 CVEsclient16 CVEsichain15 CVEsbordermanager13 CVEslinux desktop12 CVEssuse studio onsite12 CVEsdata synchronizer7 CVEsgroupwise webaccess7 CVEsleap7 CVEsmobility pack7 CVEsfile reporter7 CVEsaccess manager6 CVEsfilr6 CVEsgroupwise messenger6 CVEsidentity manager roles based provisioning module6 CVEssuse manager6 CVEszenworks6 CVEssuse lifecycle management server5 CVEsiprint client5 CVEsmoonlight5 CVEsidentity manager4 CVEsservice desk4 CVEszenworks handheld management4 CVEszenworks asset management3 CVEssuse openstack cloud3 CVEssuse linux enterprise module for web scripting3 CVEsnetware client3 CVEszenworks desktops3 CVEsvibe onprem2 CVEsmessenger2 CVEsnetmail xe2 CVEsidentity manager user application2 CVEsnovell client for windows2 CVEsopensuse build service2 CVEsopensuse factory2 CVEssecurelogin2 CVEssentinel log manager2 CVEssmall business suite2 CVEssuse cloud2 CVEssuse linux enterprise module for legacy software2 CVEsemframe2 CVEssuse linux enterprise point of sale2 CVEsclient firewall2 CVEssuse linux for vmware2 CVEssuse linux sdk2 CVEssuse manager proxy2 CVEsteaming2 CVEsunixware2 CVEsweb server2 CVEszenworks servers2 CVEszenworks desktop management2 CVEszenworks mobile management2 CVEszenworks patch management server2 CVEssuse linux enterprise for sap applications1 CVEsextend director1 CVEszenworks patch management update agent1 CVEsnetidentity client1.2.31 CVEsinternet messaging system1 CVEsaccess manager identity server1 CVEscloud manager1 CVEsclient login extension \(cle\)1 CVEssuse linux enterprise server for sap1 CVEszenworks configuration manager1 CVEschallenge response client1 CVEszenworks remote management1 CVEsmodular authentication service1 CVEszenworks server management1 CVEszenworks endpoint security management1 CVEsnetiq idm servicenow driver1 CVEsapparmor1 CVEsapache http server1 CVEsiprint open enterprise server1 CVEskanaka1 CVEsopen desktop server1 CVEsidentity manager identity applications1 CVEsopen enterprise server 111 CVEsopen enterprise server 20151 CVEsopensuse1 CVEsuser application1 CVEslibzypp1 CVEsopensuse leap1 CVEsopensuse swamp1 CVEsweb search1 CVEsiprint open enterprise server 21 CVEsnsure audit1 CVEswebyast appliance1 CVEssuse audit log keeper1 CVEsxtier framework1 CVEsnovell forum1 CVEsimonitor1 CVEssuse linux enterprise1 CVEshttp server1 CVEsfile reporter engine1 CVEs

Recent Vulnerabilities

View all 675
CVE-2025-36049HIGH 8.8

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.

CVE-2025-36048HIGH 7.2

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges.

CVE-2024-12084CRITICAL 9.8

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

CVE-2024-12088MEDIUM 6.5

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

CVE-2021-25252MEDIUM 5.5

Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.

CVE-2020-8118MEDIUM 5.0

An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.

CVE-2015-6815LOW 3.5

The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.

CVE-2012-6345HIGH 7.5

Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.

CVE-2012-6344MEDIUM 6.1

Novell ZENworks Configuration Management before 11.2.4 allows XSS.

CVE-2013-4357HIGH 7.5

The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.

CVE-2013-2016HIGH 7.8

A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host.

CVE-2019-13730HIGH 8.8

Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2019-9811HIGH 8.3

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVE-2019-11717MEDIUM 5.3

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVE-2019-11338HIGH 8.8

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

CVE-2017-9277

The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.

CVE-2017-9267

In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.

CVE-2017-14496

Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

CVE-2017-14495

Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.

CVE-2017-14494

dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.

CVE-2017-14492

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.

CVE-2017-13704

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.

CVE-2016-5759

The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.

CVE-2015-0786

Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2015-0785

com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders via the dirname variable.