« Volver al listado

CVE-2011-4189

Estado: ModificadaAlta (7.5)—

The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via a long e-mail address in an Address Book (aka .NAB) file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-4189",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-03-02T22:55:01.167",
  "references": [
    {
      "url": "http://osvdb.org/79720",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/48199",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.novell.com/support/viewContent.do?externalId=7010205",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=37&Itemid=37",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/52233",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1026753",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=733885",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73588",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/79720",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/48199",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.novell.com/support/viewContent.do?externalId=7010205",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=37&Itemid=37",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/52233",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1026753",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=733885",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73588",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via a long e-mail address in an Address Book (aka .NAB) file."
    },
    {
      "lang": "es",
      "value": "El cliente de Novell GroupWise 8.0x hasta la versión 8.02HP3 permite a atacantes remotos ejecutar código arbitrario o provocar una denegación de servicio (corrupción de memoria dinámica y caída de la aplicación) a través de una dirección de e-mail extensa en una libreta de direcciones (archivo .NAB)."
    }
  ],
  "lastModified": "2026-06-16T23:34:33.730",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:novell:groupwise:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C52E2ABC-20AE-437A-83B0-2E0753787FB5"
            },
            {
              "criteria": "cpe:2.3:a:novell:groupwise:8.0:hp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97206FE4-E1F1-40EC-BC01-A0125FB3B20F"
            },
            {
              "criteria": "cpe:2.3:a:novell:groupwise:8.0:hp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9F7E2A4-3273-45C6-B06E-D6FC22E21DE5"
            },
            {
              "criteria": "cpe:2.3:a:novell:groupwise:8.0:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9E85196-23A6-4B9C-9F3D-DDAF86FB7EA3"
            },
            {
              "criteria": "cpe:2.3:a:novell:groupwise:8.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1B3A28C-0A95-4470-9EDA-B87B40E88D0C"
            },
            {
              "criteria": "cpe:2.3:a:novell:groupwise:8.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "854578B7-5267-4A74-89A9-05998C04FC40"
            },
            {
              "criteria": "cpe:2.3:a:novell:groupwise:8.0.2:hp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B80A89E-8BD3-4C78-A672-6E16EB396DA0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}