Vulnerabilities (CVE)

Vendor filter

Novell Subscribe

Filter

1545 total CVE
CVE Vendors Products Updated CVSS
CVE-2014-9761 6 Gnu, Suse, Fedoraproject and 3 more 10 Linux Enterprise Software Development Kit, Ubuntu Linux, Linux Enterprise Desktop and 7 more 2019-06-13 7.5
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan,...
CVE-2014-9402 4 Gnu, Canonical, Novell and 1 more 4 Ubuntu Linux, Glibc, Opensuse and 1 more 2019-06-13 7.8
The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a...
CVE-2014-4043 3 Gnu, Novell, Opensuse 3 Glibc, Opensuse, Opensuse 2019-06-13 7.5
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
CVE-2016-1234 4 Fedoraproject, Gnu, Novell and 1 more 5 Glibc, Fedora, Opensuse and 2 more 2019-05-31 5.0
Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name.
CVE-2016-5760 1 Novell 1 Groupwise 2019-05-30 4.3
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to...
CVE-2016-5761 1 Novell 1 Groupwise 2019-05-30 4.3
Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email.
CVE-2016-5762 1 Novell 1 Groupwise 2019-05-30 7.5
Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a heap-based buffer overflow.
CVE-2016-0611 5 Novell, Oracle, Canonical and 2 more 7 Ubuntu Linux, Leap, Enterprise Linux and 4 more 2019-05-01 4.0
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
CVE-2017-1000366 9 Gnu, Redhat, Suse and 6 more 24 Glibc, Enterprise Linux, Linux Enterprise Server For Raspberry Pi and 21 more 2019-04-26 7.2
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been...
CVE-2014-7926 8 Google, Icu Project, Oracle and 5 more 11 Ubuntu Linux, International Components For Unicode, Enterprise Linux Desktop Supplementary and 8 more 2019-04-23 7.5
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have...
CVE-2014-7923 8 Google, Icu Project, Oracle and 5 more 11 Ubuntu Linux, International Components For Unicode, Enterprise Linux Desktop Supplementary and 8 more 2019-04-23 7.5
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have...
CVE-2016-4448 9 Apple, Slackware, Oracle and 6 more 21 Libxml2, Tvos, Suse Linux Enterprise Software Development Kit and 18 more 2019-04-22 10.0
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
CVE-2016-2047 7 Mariadb, Oracle, Novell and 4 more 8 Leap, Mariadb, Enterprise Linux and 5 more 2019-04-22 4.3
The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly...
CVE-2016-0646 7 Oracle, Redhat, Ibm and 4 more 8 Leap, Linux, Debian Linux and 5 more 2019-04-22 4.0
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DML.
CVE-2013-0223 4 Gnu, Novell, Redhat and 1 more 4 Coreutils, Enterprise Linux, Opensuse and 1 more 2019-04-22 1.9
The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the join command, when using the -i switch, which triggers a stack-based buffer...
CVE-2013-0221 4 Gnu, Novell, Redhat and 1 more 4 Coreutils, Enterprise Linux, Opensuse and 1 more 2019-04-22 4.3
The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command, when using the (1) -d or (2) -M switch, which triggers a...
CVE-2016-0648 7 Oracle, Redhat, Ibm and 4 more 8 Leap, Linux, Debian Linux and 5 more 2019-04-22 4.0
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to PS.
CVE-2015-0410 6 Novell, Debian, Oracle and 3 more 10 Ubuntu Linux, Jre, Debian Linux and 7 more 2019-04-22 5.0
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via...
CVE-2016-0666 7 Oracle, Redhat, Ibm and 4 more 8 Leap, Linux, Debian Linux and 5 more 2019-04-22 3.5
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to...
CVE-2016-0643 7 Oracle, Redhat, Ibm and 4 more 7 Leap, Debian Linux, Enterprise Linux and 4 more 2019-04-22 4.0
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect confidentiality via vectors related to DML.