Novell Groupwise vulnerabilities

74 known vulnerabilities affecting novell/groupwise.

Total CVEs
74
CISA KEV
0
Public exploits
17
Exploited in wild
0
Severity breakdown
CRITICAL24HIGH6MEDIUM43LOW1

Vulnerabilities

Page 4 of 4
CVE-2005-2346HIGHCVSS 7.5v6.52005-08-03
CVE-2005-2346 [HIGH] CVE-2005-2346: Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in the Group Task section.
nvd
CVE-2005-0296MEDIUMCVSS 5.0v6.0v6.52005-01-17
CVE-2005-0296 [MEDIUM] CVE-2005-0296: NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess al NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page. NOTE: the vendor
nvd
CVE-2003-1551CRITICALCVSS 10.0≤ 6.0_sp32003-12-31
CVE-2003-1551 [CRITICAL] CVE-2003-1551: Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact a Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."
nvd
CVE-2002-1088HIGHCVSS 7.5v6.0v6.0.12002-10-04
CVE-2002-1088 [HIGH] CVE-2002-1088: Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrar Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.
nvd
CVE-2002-0341MEDIUMCVSS 5.0v5.52002-06-25
CVE-2002-0341 [MEDIUM] CVE-2002-0341: GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to deter GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
nvd
CVE-2002-0303MEDIUMCVSS 4.6v6.02002-05-31
CVE-2002-0303 [MEDIUM] CVE-2002-0303: GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.
nvd
CVE-2001-1195HIGHCVSS 7.5PoCv5.5v6.02001-12-15
CVE-2001-1195 [HIGH] CVE-2001-1195: Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for t Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges.
nvd
CVE-2001-1458MEDIUMCVSS 5.0v5.5v6.02001-10-15
CVE-2001-1458 [MEDIUM] CVE-2001-1458: Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read ar Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.
nvd
CVE-2001-1232MEDIUMCVSS 5.0v5.52001-08-14
CVE-2001-1232 [MEDIUM] CVE-2001-1232: GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary d GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".
nvd
CVE-2001-1231MEDIUMCVSS 5.0v5.5v6.02001-08-14
CVE-2001-1231 [MEDIUM] CVE-2001-1231: GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arb GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.
nvd
CVE-2001-0355MEDIUMCVSS 5.0v5.52001-06-27
CVE-2001-0355 [MEDIUM] CVE-2001-0355: Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementat Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementation error in Groupwise system policies.
nvd
CVE-2000-0146MEDIUMCVSS 5.0PoCv5.52000-02-07
CVE-2000-0146 [MEDIUM] CVE-2000-0146: The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet.
nvd
CVE-1999-1005MEDIUMCVSS 5.0PoCv5.2v5.51999-12-19
CVE-1999-1005 [MEDIUM] CVE-1999-1005: Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.
nvd
CVE-1999-1006MEDIUMCVSS 5.0v5.2v5.51999-12-19
CVE-1999-1006 [MEDIUM] CVE-1999-1006: Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.
nvd