Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Novell

First CVE: Sep 16, 1993Active for: 33 yearsTotal CVEs: 675
54.0
VTI Score
TOP TARGET

Novell's vulnerability footprint spans a broadly represented portfolio centered on SUSE Linux Enterprise Server and Desktop distributions, GroupWise messaging, and legacy NetWare infrastructure, reflecting decades of enterprise system and collaboration product development. The vendor's disclosures acquire public exploit code with elevated frequency, reflecting both the open-source nature of SUSE Linux and the appeal of enterprise platforms to security researchers and tool developers. Recurring weakness classes include memory-buffer boundary violations, cross-site scripting in web-facing components, and sensitive-information exposure, patterns typical of large native codebases and long-lived server products that accumulate handling complexity across protocol implementations and user-interaction surfaces. Defenders should prioritize SUSE Linux Enterprise patches within their infrastructure inventory and monitor GroupWise deployments for input-validation and authentication issues; current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
675
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Novell over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 1993
32 years ago
Most Recent CVE
Jun 18, 2025
404 days ago

Products(111 total)

Top CVEs

Signals from CVEs in this vendor scope (675 CVEs).

675 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-6271CRITICAL
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
CVE-2014-7169CRITICAL
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
CVE-2015-3043CRITICAL
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or caus
Apr 14, 20159.897YESYES
CVE-2015-0240HIGH
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on
Feb 24, 201510.089NOYES
CVE-2017-14492CRITICAL
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement req
Oct 3, 20179.887NOYES
CVE-2015-0779HIGH
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a
Jun 7, 201510.086NOYES
CVE-2013-1080HIGH
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remot
Mar 29, 201310.085NOYES
CVE-2012-4959HIGH
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) i
Nov 18, 201210.085NOYES
CVE-2010-5324HIGH
Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to ex
Jun 7, 201510.083NOYES
CVE-2011-3176HIGH
Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode
Apr 9, 201210.083NOYES
View all 675 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products675 CVEs
47%
46%
Severity distribution among all CVEs352,727 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local40 (5.9%)
Network95 (14.1%)
Unknown524 (77.6%)
Physical15 (2.2%)
Adjacent Network1 (0.1%)
Attack Complexity
Low141 (20.9%)
High10 (1.5%)
Unknown524 (77.6%)
User Interaction
None118 (17.5%)
Unknown524 (77.6%)
Required33 (4.9%)
Privileges Required
Low41 (6.1%)
High5 (0.7%)
None105 (15.6%)
Unknown524 (77.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (675 CVEs).

CISA KEV
3 CVEs
0.4% of CVEs· 99th percentile
Metasploit
47 CVEs
7.0% of CVEs· 98th percentile
Nuclei
1 CVE
0.1% of CVEs· 95th percentile
ExploitDB
122 CVEs
18.1% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Novell.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Novell — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Novell's Products

View all 15 CNAs →

Top CWEs