Novell Groupwise Messenger vulnerabilities
6 known vulnerabilities affecting novell/groupwise_messenger.
Total CVEs
6
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL3MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2013-1085CRITICALCVSS 9.3≤ 2.0.4v1.0.6+2 more2013-03-29
CVE-2013-1085 [CRITICAL] CWE-119 CVE-2013-1085: Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earl
Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earlier, and Novell Messenger 2.1.x and 2.2.x before 2.2.2, allows remote attackers to execute arbitrary code via an import command containing a long string in the filename parameter.
nvd
CVE-2011-3179MEDIUMCVSS 5.0≤ 2.0.4v1.0.6+4 more2011-12-08
CVE-2011-3179 [MEDIUM] CWE-200 CVE-2011-3179: The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.
The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.04 and earlier, allows remote attackers to read from arbitrary memory locations via a crafted command.
nvd
CVE-2008-2703CRITICALCVSS 10.0PoCv2.0v2.0.2+1 more2008-06-13
CVE-2008-2703 [CRITICAL] CWE-119 CVE-2008-2703: Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 f
Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow remote attackers to execute arbitrary code via "spoofed server responses" that contain a long string after the NM_A_SZ_TRANSACTION_ID field name.
nvd
CVE-2008-2704MEDIUMCVSS 5.0v1.0.6v2.0+2 more2008-06-13
CVE-2008-2704 [MEDIUM] CWE-20 CVE-2008-2704: Novell GroupWise Messenger (GWIM) before 2.0.3 Hot Patch 1 allows remote attackers to cause a denial
Novell GroupWise Messenger (GWIM) before 2.0.3 Hot Patch 1 allows remote attackers to cause a denial of service (crash) via a long user ID, possibly involving a popup alert. NOTE: it is not clear whether this issue crosses privilege boundaries.
nvd
CVE-2006-4511MEDIUMCVSS 5.0v1.0.6v2.0.22006-10-05
CVE-2006-4511 [MEDIUM] CVE-2006-4511: Messenger Agents (nmma.exe) in Novell GroupWise 2.0.2 and 1.0.6 allows remote attackers to cause a d
Messenger Agents (nmma.exe) in Novell GroupWise 2.0.2 and 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted HTTP POST request to TCP port 8300 with a modified val parameter, which triggers a null dereference related to "zero-size strings in blowfish routines."
nvd
CVE-2006-0992CRITICALCVSS 10.0PoCv2.02006-04-14
CVE-2006-0992 [CRITICAL] CVE-2006-0992: Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote att
Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon. NOTE: due to a typo, the original ZDI advisory accidentally referenced CVE-2006-0092. This is the correct identifier.
nvd