Skip to main content

Vendor/product archive

novell / groupwise CVEs

Beta · best-effort

75 CVEs tagged to novell / groupwise24 Critical, 6 High, 44 Medium, 1 Low, 0 Unrated.

CVE-2016-5762

Published Apr 20, 2017

Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) usern…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-5761

Published Apr 20, 2017

Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-5760

Published Apr 20, 2017

Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arb…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-9169

Published Mar 23, 2017

A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacke…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0611

Published Jul 22, 2015

Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014 before Support Pack 2 allow remote attackers to inject arb…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0610

Published Sep 5, 2014

The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (in…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0600

Published Aug 29, 2014

FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave pa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-1087

Published Jul 15, 2013

Cross-site scripting (XSS) vulnerability in the client in Novell GroupWise through 8.0.3 HP3, and 2012 through SP2, on Windows allows user-assisted remote attackers to inject arbi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1086

Published Apr 19, 2013

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0804

Published Feb 24, 2013

The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer deref…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0439

Published Feb 24, 2013

An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-4912

Published Sep 28, 2012

Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0419

Published Sep 28, 2012

Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0418

Published Sep 28, 2012

Unspecified vulnerability in the client in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 on Windows allows user-assisted remote attackers to execute ar…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0417

Published Sep 28, 2012

Integer overflow in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to execute arbitrary code…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0272

Published Sep 19, 2012

Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0271

Published Sep 19, 2012

Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attacke…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3827

Published Sep 19, 2012

The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0410

Published Jul 5, 2012

Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attackers to read arbitrary files via the User.interface parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4189

Published Mar 2, 2012

The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2663

Published Oct 8, 2011

Array index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted yearly RRULE variable in a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-2662

Published Oct 8, 2011

Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a negative BYWEEKNO property i…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-2661

Published Oct 8, 2011

Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Direc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2219

Published Oct 8, 2011

Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vec…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2218

Published Oct 8, 2011

Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vec…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 75 CVEsPage 1 of 3