CVE-2008-2069
- EPSS 19.26%
- Published 02.05.2008 23:20:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI.
CVE-2008-1330
- EPSS 0.49%
- Published 18.03.2008 17:44:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with...
CVE-2007-6435
- EPSS 38.76%
- Published 18.12.2007 20:46:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in Novell GroupWise before 6.5.7, when HTML preview of e-mail is enabled, allows user-assisted remote attackers to execute arbitrary code via a long SRC attribute in an IMG element when forwarding or replying to a crafted ...
CVE-2007-3571
- EPSS 0.12%
- Published 05.07.2007 19:30:00
- Last modified 09.04.2025 00:30:58
The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP...
CVE-2007-2513
- EPSS 2.97%
- Published 04.06.2007 16:30:00
- Last modified 09.04.2025 00:30:58
Novell GroupWise 7 before SP2 20070524, and GroupWise 6 before 6.5 post-SP6 20070522, allows remote attackers to obtain credentials via a man-in-the-middle attack.
- EPSS 34.87%
- Published 24.04.2007 20:19:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via long base64 content in an HTTP Basic Authentication request.
CVE-2006-4220
- EPSS 0.62%
- Published 31.12.2006 05:00:00
- Last modified 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and ...
- EPSS 1.44%
- Published 29.06.2006 17:05:00
- Last modified 03.04.2025 01:03:51
Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow users to obtain "random programmatic access" to other email within the same post office.
- EPSS 5.3%
- Published 04.10.2005 21:02:00
- Last modified 03.04.2025 01:03:51
Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key.
- EPSS 1.76%
- Published 17.08.2005 04:00:00
- Last modified 03.04.2025 01:03:51
grpWise.exe for Novell GroupWise client 5.5 through 6.5.2 stores the password in plaintext in memory, which allows attackers to obtain the password using a debugger or another mechanism to read process memory.