Novell's vulnerability footprint spans a broadly represented portfolio centered on SUSE Linux Enterprise Server and Desktop distributions, GroupWise messaging, and legacy NetWare infrastructure, reflecting decades of enterprise system and collaboration product development. The vendor's disclosures acquire public exploit code with elevated frequency, reflecting both the open-source nature of SUSE Linux and the appeal of enterprise platforms to security researchers and tool developers. Recurring weakness classes include memory-buffer boundary violations, cross-site scripting in web-facing components, and sensitive-information exposure, patterns typical of large native codebases and long-lived server products that accumulate handling complexity across protocol implementations and user-interaction surfaces. Defenders should prioritize SUSE Linux Enterprise patches within their infrastructure inventory and monitor GroupWise deployments for input-validation and authentication issues; current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Novell over time
Signals from CVEs in this vendor scope (675 CVEs).
675 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2015-3043CRITICAL Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or caus | Apr 14, 2015 | 9.8 | 97 | YES | YES |
CVE-2015-0240HIGH The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on | Feb 24, 2015 | 10.0 | 89 | NO | YES |
CVE-2017-14492CRITICAL Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement req | Oct 3, 2017 | 9.8 | 87 | NO | YES |
CVE-2015-0779HIGH Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a | Jun 7, 2015 | 10.0 | 86 | NO | YES |
CVE-2013-1080HIGH The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remot | Mar 29, 2013 | 10.0 | 85 | NO | YES |
CVE-2012-4959HIGH Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) i | Nov 18, 2012 | 10.0 | 85 | NO | YES |
CVE-2010-5324HIGH Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to ex | Jun 7, 2015 | 10.0 | 83 | NO | YES |
CVE-2011-3176HIGH Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode | Apr 9, 2012 | 10.0 | 83 | NO | YES |
Signals from CVEs in this vendor scope (675 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Novell.
Media articles that mention a CVE ID that affects a product developed by Novell — matched by CVE ID, not by vendor name.