CVE-2012-0439
Estado: ModificadaAlta (9.3)—
An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 39%
- Percentil entre todas las CVEs puntuadas: 99
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
- http://www.novell.com/support/kb/doc.php?id=7011688
- http://www.zerodayinitiative.com/advisories/ZDI-13-008/
- https://bugzilla.novell.com/show_bug.cgi?id=712144
- https://bugzilla.novell.com/show_bug.cgi?id=743674
- http://www.novell.com/support/kb/doc.php?id=7011688
- http://www.zerodayinitiative.com/advisories/ZDI-13-008/
- https://bugzilla.novell.com/show_bug.cgi?id=712144
- https://bugzilla.novell.com/show_bug.cgi?id=743674
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-0439",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-02-24T04:37:19.907",
"references": [
{
"url": "http://www.novell.com/support/kb/doc.php?id=7011688",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-13-008/",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.novell.com/show_bug.cgi?id=712144",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.novell.com/show_bug.cgi?id=743674",
"source": "cve@mitre.org"
},
{
"url": "http://www.novell.com/support/kb/doc.php?id=7011688",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-13-008/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.novell.com/show_bug.cgi?id=712144",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.novell.com/show_bug.cgi?id=743674",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method."
},
{
"lang": "es",
"value": "Un control ActiveX en gwcls1.dll en el cliente de Novell GroupWise v8.0 antes de v8.0.3 HP2 y 2012 SP1 antes de HP1 permite a atacantes remotos ejecutar código arbitrario a través de (1) un argumento puntero al método SetEngine o (2) un argumento puntero a XPItem a un método no especificado."
}
],
"lastModified": "2026-06-16T23:37:16.050",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:novell:groupwise:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C52E2ABC-20AE-437A-83B0-2E0753787FB5"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:8.00:hp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4554A278-4BB9-4F1D-A92B-FCBCF658DA4D"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:8.00:hp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D45BA533-D0CE-4739-ADD4-E657FF91BD94"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:8.00:hp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "05E34CD7-0B83-4C9E-95B3-C656B8AF79CB"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:8.01:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "892B744B-D807-41CC-9852-3606A0B1A676"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:8.01:hp:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42FB568C-5BC1-4A47-A10D-B032E15A9A0C"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:8.02:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3414CA73-0BEA-4FC4-8E14-CF2C30FC10E3"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:8.02:hp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30A35C50-53F0-4A0C-AEF5-93E89B50F25C"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:8.02:hp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DDD788A1-C7C2-4146-B04B-A455F113D32C"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:8.02:hp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E1E087E9-CE0A-464B-ADD3-0634961B0CCC"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:8.03:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38F289E2-A937-4891-AE7B-D4F7867D6D65"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:8.03:hp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C387C08-130F-415F-8B19-437BBF126027"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:novell:groupwise:2012:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A002FE85-5FE4-4C03-A212-40263C5A2198"
},
{
"criteria": "cpe:2.3:a:novell:groupwise:2012:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D0EEEFB-A718-4A09-B9F7-1196025584B6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}