cbcvebase.

Novell Groupwise vulnerabilities

74 known vulnerabilities affecting novell/groupwise.

Total CVEs
74
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL24HIGH6MEDIUM43LOW1

Vulnerabilities

Page 2 of 4
CVE-2010-4325P3CRITICALCVSS 10.0≤ 8.0.2v4.1+21 more2011-01-28
CVE-2010-4325 [CRITICAL] CWE-119 CVE-2010-4325: Buffer overflow in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP2 Buffer overflow in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP2 allows remote attackers to execute arbitrary code via a crafted TZID variable in a VCALENDAR message.
nvd
CVE-2009-1636P3CRITICALCVSS 10.0v7.0v7.0.0+5 more2009-05-26
CVE-2009-1636 [CRITICAL] CWE-119 CVE-2009-1636: Multiple buffer overflows in the Internet Agent (aka GWIA) component in Novell GroupWise 7.x before Multiple buffer overflows in the Internet Agent (aka GWIA) component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to execute arbitrary code via (1) a crafted e-mail address in an SMTP session or (2) an SMTP command.
nvd
CVE-2012-0417P3CRITICALCVSS 10.0v8.0v8.00+3 more2012-09-28
CVE-2012-0417 [CRITICAL] CWE-189 CVE-2012-0417: Integer overflow in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 an Integer overflow in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-1999-1005P4MEDIUMCVSS 5.0PoCv5.2v5.51999-12-19
CVE-1999-1005 [MEDIUM] CVE-1999-1005: Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.
nvd
CVE-2010-4713P3CRITICALCVSS 10.0≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4713 [CRITICAL] CWE-189 CVE-2010-4713: Integer signedness error in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8 Integer signedness error in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a signed integer value in the Content-Type header.
nvd
CVE-2011-2662P3CRITICALCVSS 10.0v8.02011-10-08
CVE-2011-2662 [CRITICAL] CWE-189 CVE-2011-2662: Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allow Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a negative BYWEEKNO property in a weekly RRULE variable in a VCALENDAR attachment in an e-mail message.
nvd
CVE-2011-0333P3CRITICALCVSS 10.0v8.02011-10-08
CVE-2011-0333 [CRITICAL] CWE-119 CVE-2011-0333: Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWis Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted TZNAME variable in a VCALENDAR attachment in an e-mail message, related to an "integer truncation error."
nvd
CVE-2012-0418P3CRITICALCVSS 9.3v8.0v8.00+3 more2012-09-28
CVE-2012-0418 [CRITICAL] CVE-2012-0418: Unspecified vulnerability in the client in Novell GroupWise 8.0 before Support Pack 3 and 2012 befor Unspecified vulnerability in the client in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted file.
nvd
CVE-2014-0610P3CRITICALCVSS 10.0≤ 8.03v8.0+6 more2014-09-05
CVE-2014-0610 [CRITICAL] CVE-2014-0610: The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows all The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.
nvd
CVE-2014-0600P3HIGHCVSS 7.8v20142014-08-29
CVE-2014-0600 [HIGH] CWE-200 CVE-2014-0600: FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote at FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.
nvd
CVE-2009-3863P4MEDIUMCVSS 5.0PoCv7.0.3.12942009-11-04
CVE-2009-3863 [MEDIUM] CWE-119 CVE-2009-3863: Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remot Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argument to the SetFontFace method.
nvd
CVE-2000-0146P4MEDIUMCVSS 5.0PoCv5.52000-02-07
CVE-2000-0146 [MEDIUM] CVE-2000-0146: The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet.
nvd
CVE-2005-2804P4MEDIUMCVSS 5.0PoCv6.5.32005-10-04
CVE-2005-2804 [MEDIUM] CVE-2005-2804: Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allo Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key.
nvd
CVE-2007-6435P3CRITICALCVSS 9.3≤ 6.5.62007-12-18
CVE-2007-6435 [CRITICAL] CWE-119 CVE-2007-6435: Stack-based buffer overflow in Novell GroupWise before 6.5.7, when HTML preview of e-mail is enabled Stack-based buffer overflow in Novell GroupWise before 6.5.7, when HTML preview of e-mail is enabled, allows user-assisted remote attackers to execute arbitrary code via a long SRC attribute in an IMG element when forwarding or replying to a crafted e-mail.
nvd
CVE-2006-4220P4MEDIUMCVSS 4.3PoCv5.57ev6.5.7+2 more2006-12-31
CVE-2006-4220 [MEDIUM] CWE-79 CVE-2006-4220: Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.
nvd
CVE-2012-0410P4MEDIUMCVSS 5.0≤ 8.02v5.2+20 more2012-07-05
CVE-2012-0410 [MEDIUM] CWE-22 CVE-2012-0410: Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attacke Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attackers to read arbitrary files via the User.interface parameter.
nvd
CVE-2002-1088P4HIGHCVSS 7.5v6.0v6.0.12002-10-04
CVE-2002-1088 [HIGH] CVE-2002-1088: Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrar Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.
nvd
CVE-2005-2346P4HIGHCVSS 7.5v6.52005-08-03
CVE-2005-2346 [HIGH] CVE-2005-2346: Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in the Group Task section.
nvd
CVE-2009-0272P4MEDIUMCVSS 6.8v6.5v7.0+4 more2009-02-02
CVE-2009-0272 [MEDIUM] CWE-352 CVE-2009-0272: Cross-site request forgery (CSRF) vulnerability in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x Cross-site request forgery (CSRF) vulnerability in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allows remote attackers to insert e-mail forwarding rules, and modify unspecified other configuration settings, as arbitrary users via unknown vectors.
nvd
CVE-2016-5761P4MEDIUMCVSS 6.1≤ 2012v20142017-04-20
CVE-2016-5761 [MEDIUM] CWE-79 CVE-2016-5761: Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email.
nvd
Novell Groupwise vulnerabilities | cvebase