CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “novell”

15 vulnerabilities found for “novell”

CVE-2024-12084
CRITICAL9.8

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

samba / rsync+9
Network
Published Jan 15, 2025
CVE-2024-12088
MEDIUM6.5

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

samba / rsync+28
Network
Published Jan 14, 2025
CVE-2020-36769
HIGH7.4

The Widget Settings Importer/Exporter Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp_ajax_import_widget_dataparameter AJAX action in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

porternovelli / widget_settings_importer\/exporter
Network
Published Dec 23, 2023
CVE-2020-8118
MEDIUM5.0

An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.

nextcloud / nextcloud_server+3
Network
Published Feb 4, 2020
CVE-2015-6815
LOW3.5

The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.

qemu / qemu+29
Adjacent
Published Jan 31, 2020
CVE-2012-6344
MEDIUM6.1

Novell ZENworks Configuration Management before 11.2.4 allows XSS.

novell / zenworks_configuration_management
Network
Published Jan 25, 2020
CVE-2012-6345
HIGH7.5

Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.

novell / zenworks_configuration_management
Network
Published Jan 25, 2020
CVE-2013-4357
HIGH7.5

The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.

eglibc / eglibc+8
Network
Published Dec 31, 2019
CVE-2013-2016
HIGH7.8

A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host.

qemu / qemu+6
Local
Published Dec 30, 2019
CVE-2019-13730
HIGH8.8

Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

google / chrome+10
Network
Published Dec 10, 2019
CVE-2019-9811
HIGH8.3

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

mozilla / firefox+6
Network
Published Jul 23, 2019
CVE-2019-11717
MEDIUM5.3

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

mozilla / firefox+6
Network
Published Jul 23, 2019
CVE-2019-11338
HIGH8.8

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

ffmpeg / ffmpeg+9
Network
Published Apr 19, 2019
CVE-2017-9267
MEDIUM6.5

In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.

novell / edirectory
Network
Published Mar 2, 2018
CVE-2017-9277
MEDIUM4.2

The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.

novell / edirectory+3
Adjacent
Published Mar 2, 2018