Novell
Novell Groupwise: vulnerabilidades y CVE
Novell Groupwise tiene 75 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE75
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2016-5762 | Crítica (9.8) | 5.7% | — | 20 abr 2017 | Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a… |
| CVE-2016-5761 | Media (6.1) | 1.3% | — | 20 abr 2017 | Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email. |
| CVE-2016-5760 | Media (6.1) | 1.3% | — | 20 abr 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1)… |
| CVE-2016-9169 | Media (6.1) | 0.85% | — | 23 mar 2017 | A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScript in the context… |
| CVE-2014-0611 | Media (4.3) | 2.3% | — | 22 jul 2015 | Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014 before Support Pack 2 allow remote attackers to inject arbitrary web script or HTML via… |
| CVE-2014-0610 | Alta (10) | 5.5% | — | 5 sept 2014 | The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via… |
| CVE-2014-0600 | Alta (7.8) | 3.1% | — | 29 ago 2014 | FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287. |
| CVE-2013-1087 | Media (4.3) | 1.5% | — | 15 jul 2013 | Cross-site scripting (XSS) vulnerability in the client in Novell GroupWise through 8.0.3 HP3, and 2012 through SP2, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML via the body of… |
| CVE-2013-1086 | Media (4.3) | 1.2% | — | 19 abr 2013 | Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError attribute. |
| CVE-2013-0804 | Alta (10) | 12% | — | 24 feb 2013 | The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via unspecified vectors. |
| CVE-2012-0439 | Alta (9.3) | 39% | — | 24 feb 2013 | An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2)… |
| CVE-2012-4912 | Media (4.3) | 1.5% | — | 28 sept 2012 | Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to inject arbitrary web script or HTML via a… |
| CVE-2012-0419 | Media (5) | 42% | — | 28 sept 2012 | Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrary files via directory traversal… |
| CVE-2012-0418 | Alta (9.3) | 3.7% | — | 28 sept 2012 | Unspecified vulnerability in the client in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted file. |
| CVE-2012-0417 | Alta (10) | 5.6% | — | 28 sept 2012 | Integer overflow in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors. |
| CVE-2012-0272 | Media (4.3) | 1.3% | — | 19 sept 2012 | Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to inject arbitrary web script or HTML via the merge parameter. |
| CVE-2012-0271 | Alta (10) | 17% | — | 19 sept 2012 | Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a… |
| CVE-2011-3827 | Media (4.3) | 3.7% | — | 19 sept 2012 | The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a… |
| CVE-2012-0410 | Media (5) | 3.7% | — | 5 jul 2012 | Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attackers to read arbitrary files via the User.interface parameter. |
| CVE-2011-4189 | Alta (7.5) | 12% | — | 2 mar 2012 | The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via a long e-mail address in an Address… |
| CVE-2011-2663 | Alta (10) | 5.4% | — | 8 oct 2011 | Array index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted yearly RRULE variable in a VCALENDAR attachment in an e-mail… |
| CVE-2011-2662 | Alta (10) | 4.1% | — | 8 oct 2011 | Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a negative BYWEEKNO property in a weekly RRULE variable in a VCALENDAR… |
| CVE-2011-2661 | Media (4.3) | 0.94% | — | 8 oct 2011 | Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Directory.Item.name or (2)… |
| CVE-2011-2219 | Media (5) | 1.1% | — | 8 oct 2011 | Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than… |
| CVE-2011-2218 | Media (5) | 1.1% | — | 8 oct 2011 | Unspecified vulnerability in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, a different vulnerability than… |
| CVE-2011-0334 | Alta (10) | 4.8% | — | 8 oct 2011 | Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file. |
| CVE-2011-0333 | Alta (10) | 6.2% | — | 8 oct 2011 | Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a… |
| CVE-2010-4717 | Media (6.5) | 9.9% | — | 31 ene 2011 | Multiple stack-based buffer overflows in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a long (1) LIST or (2) LSUB… |
| CVE-2010-4716 | Media (4.3) | 1.8% | — | 31 ene 2011 | Cross-site scripting (XSS) vulnerability in the WebPublisher component in Novell GroupWise before 8.02HP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2010-4715 | Media (5) | 28% | — | 31 ene 2011 | Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agent components in Novell GroupWise before 8.02HP allow remote attackers to read arbitrary files via unspecified vectors.… |
Otros productos de Novell
Suse Linux Enterprise Server · 91Suse Linux Enterprise Desktop · 83Netware · 72Suse Linux Enterprise Software Development KIT · 65Edirectory · 51Zenworks Configuration Management · 35Suse Linux Enterprise Real Time Extension · 33Iprint · 30Suse Linux Enterprise Workstation Extension · 24Suse Linux Enterprise Debuginfo · 24Suse Linux Enterprise Module FOR Public Cloud · 22Suse Linux Enterprise Live Patching · 22