Novell
628 CVEs tracked since 1999. Since Apr 2011, 3 of them reached CISA KEV.
Novell CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2011-04 | 9 | 0 |
| 2011-05 | 1 | 0 |
| 2011-06 | 11 | 0 |
| 2011-07 | 2 | 0 |
| 2011-08 | 17 | 0 |
| 2011-09 | 1 | 0 |
| 2011-10 | 11 | 0 |
| 2011-11 | 2 | 0 |
| 2011-12 | 4 | 0 |
| 2012-01 | null or fewer | |
| 2012-02 | 4 | 0 |
| 2012-03 | 1 | 0 |
| 2012-04 | 5 | 0 |
| 2012-05 | null or fewer | |
| 2012-06 | 3 | 0 |
| 2012-07 | 4 | 0 |
| 2012-08 | null or fewer | |
| 2012-09 | 7 | 0 |
| 2012-10 | 1 | 0 |
| 2012-11 | 4 | 0 |
| 2012-12 | 1 | 0 |
| 2013-01 | null or fewer | |
| 2013-02 | 2 | 0 |
| 2013-03 | 7 | 0 |
| 2013-04 | 5 | 0 |
| 2013-05 | 2 | 0 |
| 2013-06 | 4 | 0 |
| 2013-07 | 4 | 0 |
| 2013-08 | 1 | 0 |
| 2013-09 | null or fewer | |
| 2013-10 | 1 | 0 |
| 2013-11 | 7 | 0 |
| 2013-12 | 10 | 0 |
| 2014-01 | null or fewer | |
| 2014-02 | null or fewer | |
| 2014-03 | 2 | 0 |
| 2014-04 | 2 | 0 |
| 2014-05 | 1 | 0 |
| 2014-06 | 2 | 0 |
| 2014-07 | null or fewer | |
| 2014-08 | 2 | 0 |
| 2014-09 | 4 | 2 |
| 2014-10 | 2 | 0 |
| 2014-11 | 3 | 0 |
| 2014-12 | 2 | 0 |
| 2015-01 | 11 | 0 |
| 2015-02 | 1 | 0 |
| 2015-03 | null or fewer | |
| 2015-04 | 10 | 1 |
| 2015-05 | 5 | 0 |
| 2015-06 | 3 | 0 |
| 2015-07 | 14 | 0 |
| 2015-08 | null or fewer | |
| 2015-09 | null or fewer | |
| 2015-10 | 1 | 0 |
| 2015-11 | null or fewer | |
| 2015-12 | null or fewer | |
| 2016-01 | null or fewer | |
| 2016-02 | 3 | 0 |
| 2016-03 | 7 | 0 |
| 2016-04 | 19 | 0 |
| 2016-05 | 16 | 0 |
| 2016-06 | 11 | 0 |
| 2016-07 | 5 | 0 |
| 2016-08 | null or fewer | |
| 2016-09 | 11 | 0 |
| 2016-10 | 2 | 0 |
| 2016-11 | null or fewer | |
| 2016-12 | null or fewer | |
| 2017-01 | null or fewer | |
| 2017-02 | null or fewer | |
| 2017-03 | 7 | 0 |
| 2017-04 | null or fewer | |
| 2017-05 | 4 | 0 |
| 2017-06 | null or fewer | |
| 2017-07 | 2 | 0 |
| 2017-08 | 7 | 0 |
| 2017-09 | null or fewer | |
| 2017-10 | 3 | 0 |
| 2017-11 | null or fewer | |
| 2017-12 | null or fewer | |
| 2018-01 | null or fewer | |
| 2018-02 | null or fewer | |
| 2018-03 | 2 | 0 |
| 2018-04 | null or fewer | |
| 2018-05 | null or fewer | |
| 2018-06 | null or fewer | |
| 2018-07 | null or fewer | |
| 2018-08 | null or fewer | |
| 2018-09 | null or fewer | |
| 2018-10 | null or fewer | |
| 2018-11 | null or fewer | |
| 2018-12 | null or fewer | |
| 2019-01 | null or fewer | |
| 2019-02 | null or fewer | |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | null or fewer | |
| 2019-06 | null or fewer | |
| 2019-07 | null or fewer | |
| 2019-08 | null or fewer | |
| 2019-09 | null or fewer | |
| 2019-10 | null or fewer | |
| 2019-11 | null or fewer | |
| 2019-12 | 3 | 0 |
| 2020-01 | 3 | 0 |
Products
The products that kept showing up in Novell's monthly top three, with their CVEs summed over those months.
- Suse Linux Enterprise Server80
- Suse Linux Enterprise Desktop51
- Suse Linux Enterprise Software Development Kit51
- Zenworks Configuration Management34
- Groupwise22
- Suse Linux Enterprise Real Time Extension19
- Iprint17
- Suse Linux Enterprise Workstation Extension13
- Suse Studio Onsite12
- Suse Linux Enterprise Debuginfo11
Latest CVEs
The 15 most recently published vulnerabilities affecting Novell.
- CVE-2024-12084Rsync: heap buffer overflow in rsync due to improper checksum length handling9.8
- CVE-2024-12088Rsync: --safe-links option bypass leads to path traversal6.5
- CVE-2020-8118An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.5.0
- CVE-2015-6815The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of s...3.5
- CVE-2012-6345Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.7.5
- CVE-2012-6344Novell ZENworks Configuration Management before 11.2.4 allows XSS.6.1
- CVE-2013-4357The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.7.5
- CVE-2013-2016A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, s...7.8
- CVE-2019-13730Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.8.8
- CVE-2019-9811As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This...8.3
- CVE-2019-11717A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vu...5.3
- CVE-2019-11338libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array ac...8.8
- CVE-2017-9267eDirectory LDAP peer certificate validation issue6.5
- CVE-2017-9277existing connection is being used even though eDirectory LDAP server is upgraded to EBA4.2
- CVE-2017-14496Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of servic...7.5
The record
- Peak rank
- #4 in Aug 2003
- Busiest month shown
- Apr 2016, 19 CVEs
- Months with a KEV entry
- 2 since Apr 2011
- Monthly snapshots
- 145 since 1999