Novell Groupwise vulnerabilities
74 known vulnerabilities affecting novell/groupwise.
Total CVEs
74
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL24HIGH6MEDIUM43LOW1
Vulnerabilities
Page 1 of 4
CVE-2012-0439P2CRITICALCVSS 9.3PoCv8.0v8.00+4 more2013-02-24
CVE-2012-0439 [CRITICAL] CWE-94 CVE-2012-0439: An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 bef
An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method.
nvd
CVE-2010-4711P2CRITICALCVSS 10.0PoC≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4711 [CRITICAL] CWE-399 CVE-2010-4711: Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell
Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a large parameter in a LIST command.
nvd
CVE-2012-0271P2CRITICALCVSS 10.0PoCv8.0v8.01+20 more2012-09-19
CVE-2012-0271 [CRITICAL] CWE-189 CVE-2012-0271: Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novel
Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow, as demonstrated by a request with -1 in the Content-Length HTTP header.
nvd
CVE-2010-2777P2CRITICALCVSS 9.0PoCv7.0v8.02011-01-28
CVE-2010-2777 [CRITICAL] CWE-119 CVE-2010-2777: Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novel
Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to execute arbitrary code via a long mailbox name in a CREATE command.
nvd
CVE-2008-2069P3CRITICALCVSS 9.3PoCv7.02008-05-02
CVE-2008-2069 [CRITICAL] CWE-119 CVE-2008-2069: Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execut
Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI.
nvd
CVE-2013-0804P3CRITICALCVSS 10.0PoCv8.0v8.00+4 more2013-02-24
CVE-2013-0804 [CRITICAL] CWE-78 CVE-2013-0804: The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers
The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via unspecified vectors.
nvd
CVE-2009-0410P3CRITICALCVSS 10.0PoCv6.5v7.0+4 more2009-02-03
CVE-2009-0410 [CRITICAL] CWE-119 CVE-2009-0410: Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0
Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command, leading to a buffer overflow.
nvd
CVE-2012-0419P3MEDIUMCVSS 5.0PoCv8.0v8.00+3 more2012-09-28
CVE-2012-0419 [MEDIUM] CWE-22 CVE-2012-0419: Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Suppor
Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrary files via directory traversal sequences in a request.
nvd
CVE-2009-1634P3HIGHCVSS 7.5PoCv7.0v7.0.0+4 more2009-05-26
CVE-2009-1634 [HIGH] CVE-2009-1634: The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not prop
The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.
nvd
CVE-2011-4189P3HIGHCVSS 7.5PoCv8.0v8.0.1+1 more2012-03-02
CVE-2011-4189 [HIGH] CWE-94 CVE-2011-4189: The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary cod
The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via a long e-mail address in an Address Book (aka .NAB) file.
nvd
CVE-2010-4717P3MEDIUMCVSS 6.5PoC≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4717 [MEDIUM] CWE-119 CVE-2010-4717: Multiple stack-based buffer overflows in the IMAP server component in GroupWise Internet Agent (GWIA
Multiple stack-based buffer overflows in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a long (1) LIST or (2) LSUB command.
nvd
CVE-2010-4715P3MEDIUMCVSS 5.0PoC≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4715 [MEDIUM] CWE-22 CVE-2010-4715: Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agen
Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agent components in Novell GroupWise before 8.02HP allow remote attackers to read arbitrary files via unspecified vectors. NOTE: some of these details are obtained from third party information.
nvd
CVE-2007-2171P2CRITICALCVSS 10.0v7.02007-04-24
CVE-2007-2171 [CRITICAL] CVE-2007-2171: Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) We
Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via long base64 content in an HTTP Basic Authentication request.
nvd
CVE-2001-1195P3HIGHCVSS 7.5PoCv5.5v6.02001-12-15
CVE-2001-1195 [HIGH] CVE-2001-1195: Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for t
Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges.
nvd
CVE-2016-5762P3CRITICALCVSS 9.8≤ 2012v20142017-04-20
CVE-2016-5762 [CRITICAL] CWE-190 CVE-2016-5762: Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patc
Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a heap-based buffer overflow.
nvd
CVE-2011-0334P3CRITICALCVSS 10.0v8.02011-10-08
CVE-2011-0334 [CRITICAL] CWE-119 CVE-2011-0334: Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 b
Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file.
nvd
CVE-2010-4714P3CRITICALCVSS 10.0≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4714 [CRITICAL] CWE-119 CVE-2010-4714: Multiple stack-based buffer overflows in Novell GroupWise before 8.02HP allow remote attackers to ex
Multiple stack-based buffer overflows in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) gwpoa.exe in the Post Office Agent, (2) gwmta.exe in the Message Transfer Agent, (3) gwia.exe in the Internet Agent, (4) the WebAccess Agent, or (5) the Monitor Agent.
nvd
CVE-2010-4326P3CRITICALCVSS 10.0≤ 8.0.2v4.1+21 more2011-01-28
CVE-2010-4326 [CRITICAL] CWE-119 CVE-2010-4326: Multiple buffer overflows in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise befor
Multiple buffer overflows in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via variables in a VCALENDAR message, as demonstrated by a long (1) REQUEST-STATUS, (2) TZNAME, (3) COMMENT, or (4) RRULE variable in this message.
nvd
CVE-2010-4712P3CRITICALCVSS 10.0≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4712 [CRITICAL] CWE-119 CVE-2010-4712: Multiple stack-based buffer overflows in gwia.exe in GroupWise Internet Agent (GWIA) in Novell Group
Multiple stack-based buffer overflows in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a Content-Type header containing (1) multiple items separated by ; (semicolon) characters or (2) crafted string data.
nvd
CVE-2011-2663P3CRITICALCVSS 10.0v8.02011-10-08
CVE-2011-2663 [CRITICAL] CWE-119 CVE-2011-2663: Array index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remot
Array index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted yearly RRULE variable in a VCALENDAR attachment in an e-mail message.
nvd
1 / 4Next →