Novell Groupwise vulnerabilities
74 known vulnerabilities affecting novell/groupwise.
Total CVEs
74
CISA KEV
0
Public exploits
17
Exploited in wild
0
Severity breakdown
CRITICAL24HIGH6MEDIUM43LOW1
Vulnerabilities
Page 2 of 4
CVE-2011-0334CRITICALCVSS 10.0v8.02011-10-08
CVE-2011-0334 [CRITICAL] CWE-119 CVE-2011-0334: Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 b
Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file.
nvd
CVE-2011-2662CRITICALCVSS 10.0v8.02011-10-08
CVE-2011-2662 [CRITICAL] CWE-189 CVE-2011-2662: Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allow
Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a negative BYWEEKNO property in a weekly RRULE variable in a VCALENDAR attachment in an e-mail message.
nvd
CVE-2011-0333CRITICALCVSS 10.0v8.02011-10-08
CVE-2011-0333 [CRITICAL] CWE-119 CVE-2011-0333: Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWis
Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted TZNAME variable in a VCALENDAR attachment in an e-mail message, related to an "integer truncation error."
nvd
CVE-2011-2663CRITICALCVSS 10.0v8.02011-10-08
CVE-2011-2663 [CRITICAL] CWE-119 CVE-2011-2663: Array index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remot
Array index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted yearly RRULE variable in a VCALENDAR attachment in an e-mail message.
nvd
CVE-2011-2219MEDIUMCVSS 5.0v8.02011-10-08
CVE-2011-2219 [MEDIUM] CVE-2011-2219: Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allo
Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2218.
nvd
CVE-2011-2218MEDIUMCVSS 5.0v8.02011-10-08
CVE-2011-2218 [MEDIUM] CVE-2011-2218: Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allo
Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2219.
nvd
CVE-2011-2661MEDIUMCVSS 4.3v8.02011-10-08
CVE-2011-2661 [MEDIUM] CWE-79 CVE-2011-2661: Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Directory.Item.name or (2) Directory.Item.displayName parameter.
nvd
CVE-2010-4713CRITICALCVSS 10.0≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4713 [CRITICAL] CWE-189 CVE-2010-4713: Integer signedness error in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8
Integer signedness error in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a signed integer value in the Content-Type header.
nvd
CVE-2010-4711CRITICALCVSS 10.0PoC≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4711 [CRITICAL] CWE-399 CVE-2010-4711: Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell
Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a large parameter in a LIST command.
nvd
CVE-2010-4714CRITICALCVSS 10.0≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4714 [CRITICAL] CWE-119 CVE-2010-4714: Multiple stack-based buffer overflows in Novell GroupWise before 8.02HP allow remote attackers to ex
Multiple stack-based buffer overflows in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) gwpoa.exe in the Post Office Agent, (2) gwmta.exe in the Message Transfer Agent, (3) gwia.exe in the Internet Agent, (4) the WebAccess Agent, or (5) the Monitor Agent.
nvd
CVE-2010-4712CRITICALCVSS 10.0≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4712 [CRITICAL] CWE-119 CVE-2010-4712: Multiple stack-based buffer overflows in gwia.exe in GroupWise Internet Agent (GWIA) in Novell Group
Multiple stack-based buffer overflows in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a Content-Type header containing (1) multiple items separated by ; (semicolon) characters or (2) crafted string data.
nvd
CVE-2010-4717MEDIUMCVSS 6.5PoC≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4717 [MEDIUM] CWE-119 CVE-2010-4717: Multiple stack-based buffer overflows in the IMAP server component in GroupWise Internet Agent (GWIA
Multiple stack-based buffer overflows in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a long (1) LIST or (2) LSUB command.
nvd
CVE-2010-4716MEDIUMCVSS 4.3≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4716 [MEDIUM] CWE-79 CVE-2010-4716: Cross-site scripting (XSS) vulnerability in the WebPublisher component in Novell GroupWise before 8.
Cross-site scripting (XSS) vulnerability in the WebPublisher component in Novell GroupWise before 8.02HP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-4715MEDIUMCVSS 5.0PoC≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4715 [MEDIUM] CWE-22 CVE-2010-4715: Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agen
Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agent components in Novell GroupWise before 8.02HP allow remote attackers to read arbitrary files via unspecified vectors. NOTE: some of these details are obtained from third party information.
nvd
CVE-2010-4326CRITICALCVSS 10.0≤ 8.0.2v4.1+21 more2011-01-28
CVE-2010-4326 [CRITICAL] CWE-119 CVE-2010-4326: Multiple buffer overflows in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise befor
Multiple buffer overflows in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via variables in a VCALENDAR message, as demonstrated by a long (1) REQUEST-STATUS, (2) TZNAME, (3) COMMENT, or (4) RRULE variable in this message.
nvd
CVE-2010-4325CRITICALCVSS 10.0≤ 8.0.2v4.1+21 more2011-01-28
CVE-2010-4325 [CRITICAL] CWE-119 CVE-2010-4325: Buffer overflow in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP2
Buffer overflow in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP2 allows remote attackers to execute arbitrary code via a crafted TZID variable in a VCALENDAR message.
nvd
CVE-2010-2777CRITICALCVSS 9.0PoCv7.0v8.02011-01-28
CVE-2010-2777 [CRITICAL] CWE-119 CVE-2010-2777: Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novel
Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to execute arbitrary code via a long mailbox name in a CREATE command.
nvd
CVE-2010-2778MEDIUMCVSS 4.3v7.0v8.02011-01-28
CVE-2010-2778 [MEDIUM] CWE-79 CVE-2010-2778: Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 7.x before 7.0 post-SP4 FT
Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to a "Javascript XSS exploit."
nvd
CVE-2010-2779MEDIUMCVSS 4.3v8.02011-01-28
CVE-2010-2779 [MEDIUM] CWE-79 CVE-2010-2779: Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows
Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to "replies."
nvd
CVE-2009-4662MEDIUMCVSS 4.3v7.0v7.01+2 more2010-03-03
CVE-2009-4662 [MEDIUM] CWE-79 CVE-2009-4662: Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 7.0 before 7
Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 7.0 before 7.03 HP4 and 8.0 before 8.0 SP1 allows remote attackers to inject arbitrary web script or HTML via the User.Theme.index parameter.
nvd