cbcvebase.

Novell Groupwise vulnerabilities

74 known vulnerabilities affecting novell/groupwise.

Total CVEs
74
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL24HIGH6MEDIUM43LOW1

Vulnerabilities

Page 3 of 4
CVE-2016-9169P4MEDIUMCVSS 6.1v20142017-03-23
CVE-2016-9169 [MEDIUM] CWE-79 CVE-2016-9169: A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell Group A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScript in the context of a valid user's browser session by getting the user to click on a specially crafted link. This could lead to session compromise or oth
nvd
CVE-2001-1458P4MEDIUMCVSS 5.0v5.5v6.02001-10-15
CVE-2001-1458 [MEDIUM] CVE-2001-1458: Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read ar Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.
nvd
CVE-2016-5760P4MEDIUMCVSS 6.1≤ 2012v20142017-04-20
CVE-2016-5760 [MEDIUM] CWE-79 CVE-2016-5760: Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/install/login.jsp or (2) PATH_INFO to gwadmin-console/index.jsp.
nvd
CVE-2003-1551P4CRITICALCVSS 10.0≤ 6.0_sp32003-12-31
CVE-2003-1551 [CRITICAL] CVE-2003-1551: Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact a Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."
nvd
CVE-2001-1232P4MEDIUMCVSS 5.0v5.52001-08-14
CVE-2001-1232 [MEDIUM] CVE-2001-1232: GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary d GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".
nvd
CVE-2005-2620P4MEDIUMCVSS 5.0v6.0v6.5+1 more2005-08-17
CVE-2005-2620 [MEDIUM] CVE-2005-2620: grpWise.exe for Novell GroupWise client 5.5 through 6.5.2 stores the password in plaintext in memory grpWise.exe for Novell GroupWise client 5.5 through 6.5.2 stores the password in plaintext in memory, which allows attackers to obtain the password using a debugger or another mechanism to read process memory.
nvd
CVE-2001-1231P4MEDIUMCVSS 5.0v5.5v6.02001-08-14
CVE-2001-1231 [MEDIUM] CVE-2001-1231: GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arb GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.
nvd
CVE-2011-3827P4MEDIUMCVSS 4.3≤ 8.00v8.0+1 more2012-09-19
CVE-2011-3827 [MEDIUM] CWE-119 CVE-2011-3827: The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 bef The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted date-time string in a .ics attachment.
nvd
CVE-2006-3268P4MEDIUMCVSS 5.0v5.2v5.5+6 more2006-06-29
CVE-2006-3268 [MEDIUM] CVE-2006-3268: Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow us Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow users to obtain "random programmatic access" to other email within the same post office.
nvd
CVE-2009-0274P4MEDIUMCVSS 5.0v6.5v7.0+4 more2009-02-03
CVE-2009-0274 [MEDIUM] CWE-200 CVE-2009-0274: Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, an Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 might allow remote attackers to obtain sensitive information via a crafted URL, related to conversion of POST requests to GET requests.
nvd
CVE-2014-0611P4MEDIUMCVSS 4.3≤ 2012≤ 20142015-07-22
CVE-2014-0611 [MEDIUM] CWE-79 CVE-2014-0611: Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Sup Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014 before Support Pack 2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2009-0273P4MEDIUMCVSS 4.3v6.5v7.0+4 more2009-02-02
CVE-2009-0273 [MEDIUM] CWE-79 CVE-2009-0273: Multiple cross-site scripting (XSS) vulnerabilities in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7 Multiple cross-site scripting (XSS) vulnerabilities in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allow remote attackers to inject arbitrary web script or HTML via the (1) User.id and (2) Library.queryText parameters to gw/webacc, and other vectors involving (3) HTML e-mail and (4) HTML attachments.
nvd
CVE-2001-0355P4MEDIUMCVSS 5.0v5.52001-06-27
CVE-2001-0355 [MEDIUM] CVE-2001-0355: Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementat Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementation error in Groupwise system policies.
nvd
CVE-2010-2778P4MEDIUMCVSS 4.3v7.0v8.02011-01-28
CVE-2010-2778 [MEDIUM] CWE-79 CVE-2010-2778: Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 7.x before 7.0 post-SP4 FT Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to a "Javascript XSS exploit."
nvd
CVE-2010-2779P4MEDIUMCVSS 4.3v8.02011-01-28
CVE-2010-2779 [MEDIUM] CWE-79 CVE-2010-2779: Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to "replies."
nvd
CVE-2011-2219P4MEDIUMCVSS 5.0v8.02011-10-08
CVE-2011-2219 [MEDIUM] CVE-2011-2219: Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allo Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2218.
nvd
CVE-2011-2218P4MEDIUMCVSS 5.0v8.02011-10-08
CVE-2011-2218 [MEDIUM] CVE-2011-2218: Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allo Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than CVE-2011-2219.
nvd
CVE-2010-4716P4MEDIUMCVSS 4.3≤ 8.0.2v4.1+21 more2011-01-31
CVE-2010-4716 [MEDIUM] CWE-79 CVE-2010-4716: Cross-site scripting (XSS) vulnerability in the WebPublisher component in Novell GroupWise before 8. Cross-site scripting (XSS) vulnerability in the WebPublisher component in Novell GroupWise before 8.02HP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-4912P4MEDIUMCVSS 4.3v8.0v8.00+3 more2012-09-28
CVE-2012-4912 [MEDIUM] CWE-79 CVE-2012-4912: Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before S Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to inject arbitrary web script or HTML via a crafted signature in an HTML e-mail message.
nvd
CVE-2007-2513P4MEDIUMCVSS 4.3v6.5v7.02007-06-04
CVE-2007-2513 [MEDIUM] CVE-2007-2513: Novell GroupWise 7 before SP2 20070524, and GroupWise 6 before 6.5 post-SP6 20070522, allows remote Novell GroupWise 7 before SP2 20070524, and GroupWise 6 before 6.5 post-SP6 20070522, allows remote attackers to obtain credentials via a man-in-the-middle attack.
nvd
Novell Groupwise vulnerabilities | cvebase