Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 9.7% | 💥 Exploit | Novell Groupwise | 3/2/2009 | 16/6/2026 | Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command, leading to a buffer overflow. | |
| Modificada | Media (5) | 1.3% | — | Novell Groupwise | 3/2/2009 | 16/6/2026 | Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 might allow remote attackers to obtain sensitive information via a crafted URL, related to conversion of POST requests to GET requests. | |
| Modificada | Media (4.3) | 1.7% | — | Novell Groupwise | 2/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allow remote attackers to inject arbitrary web script or HTML via the (1) User.id and (2) Library.queryText parameters to gw/webacc, and other vectors involving (3) HTML e-mail and (4) HTML… | |
| Modificada | Media (6.8) | 0.58% | — | Novell Groupwise | 2/2/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allows remote attackers to insert e-mail forwarding rules, and modify unspecified other configuration settings, as arbitrary users via unknown vectors. | |
| Modificada | Media (4.3) | 1.4% | — | Novell Groupwise | 6/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the WebAccess simple interface in Novell Groupwise 7.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 6.9% | — | Blackberry Enterprise ServerBlackberry UniteRIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server FOR Domino+3 | 21/7/2008 | 16/6/2026 | Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 and BlackBerry Enterprise Server 4.1 SP3 (4.1.3) through 4.1 SP5 (4.1.5) allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file attachment. | |
| Modificada | Media (5) | 1.8% | — | Novell Groupwise Messenger | 13/6/2008 | 16/6/2026 | Novell GroupWise Messenger (GWIM) before 2.0.3 Hot Patch 1 allows remote attackers to cause a denial of service (crash) via a long user ID, possibly involving a popup alert. NOTE: it is not clear whether this issue crosses privilege boundaries. | |
| Modificada | Alta (10) | 61% | 💥 Exploit | Novell Groupwise Messenger | 13/6/2008 | 16/6/2026 | Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow remote attackers to execute arbitrary code via "spoofed server responses" that contain a long string after the NM_A_SZ_TRANSACTION_ID field name. | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | Novell Groupwise | 2/5/2008 | 16/6/2026 | Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI. | |
| Modificada | Baja (3.5) | 1.1% | — | Novell Groupwise | 18/3/2008 | 16/6/2026 | Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with the attacker. | |
| Modificada | Alta (9.3) | 6.6% | — | Novell Groupwise | 18/12/2007 | 16/6/2026 | Stack-based buffer overflow in Novell GroupWise before 6.5.7, when HTML preview of e-mail is enabled, allows user-assisted remote attackers to execute arbitrary code via a long SRC attribute in an IMG element when forwarding or replying to a crafted e-mail. | |
| Modificada | Media (4.3) | 0.95% | — | Novell Groupwise Webaccess | 28/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the webacc servlet in Novell GroupWise 6.5 WebAccess allows remote attackers to inject arbitrary web script or HTML via the User.Id parameter, as demonstrated by a URL within a url field in a STYLE element, possibly due to an incomplete fix for CVE-2004-2103.2. | |
| Modificada | Media (4.3) | 1.2% | — | Novell Groupwise | 5/7/2007 | 16/6/2026 | The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address. | |
| Modificada | Media (4.3) | 1.4% | — | Novell Groupwise | 4/6/2007 | 16/6/2026 | Novell GroupWise 7 before SP2 20070524, and GroupWise 6 before 6.5 post-SP6 20070522, allows remote attackers to obtain credentials via a man-in-the-middle attack. | |
| Modificada | Media (6.4) | 1.5% | — | Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express | 11/5/2007 | 16/6/2026 | Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to obtain user names and other sensitive information via a direct request to (1) usrmgr/userList.asp or (2) usrmgr/userStatusList.asp. | |
| Modificada | Media (4.3) | 2.7% | — | Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express | 11/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to… | |
| Modificada | Alta (7.5) | 1.8% | — | Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express | 11/5/2007 | 16/6/2026 | usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify user account details and cause a denial of service (account deactivation) via the userid parameter in… | |
| Modificada | Alta (10) | 24% | — | Novell Groupwise | 24/4/2007 | 16/6/2026 | Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via long base64 content in an HTTP Basic Authentication request. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Novell GroupwiseNovell Groupwise Webaccess | 31/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters. | |
| Modificada | Media (5) | 3.0% | — | Novell Groupwise Messenger | 5/10/2006 | 16/6/2026 | Messenger Agents (nmma.exe) in Novell GroupWise 2.0.2 and 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted HTTP POST request to TCP port 8300 with a modified val parameter, which triggers a null dereference related to "zero-size strings in blowfish routines." | |
| Modificada | Media (4.3) | 2.0% | — | Novell Groupwise Webaccess | 11/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrated by the "+ADw-SCRIPT+AD4-" sequence. | |
| Modificada | Media (4.3) | 1.9% | — | Novell Groupwise Webaccess | 11/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login page in Novell GroupWise WebAccess 6.5 before 20060721 and WebAccess 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via the GWAP.version parameter. | |
| Modificada | Media (5) | 1.9% | — | Novell Groupwise | 29/6/2006 | 16/6/2026 | Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow users to obtain "random programmatic access" to other email within the same post office. | |
| Modificada | Alta (10) | 73% | 💥 Exploit | Novell Groupwise Messenger | 14/4/2006 | 16/6/2026 | Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon. NOTE: due to a typo, the original ZDI advisory accidentally referenced CVE-2006-0092. This is the correct identifier. | |
| Modificada | Media (5) | 5.1% | 💥 Exploit | Novell Groupwise | 4/10/2005 | 16/6/2026 | Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key. |