Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown
CVE-2010-4325
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Buffer overflow in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP2 allows remote attackers to execute arbitrary code via a crafted TZID variable in a VCALENDAR message.
0
Attacker Value
Unknown
CVE-2010-4326
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Multiple buffer overflows in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via variables in a VCALENDAR message, as demonstrated by a long (1) REQUEST-STATUS, (2) TZNAME, (3) COMMENT, or (4) RRULE variable in this message.
0
Attacker Value
Unknown
CVE-2006-4220
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.
0
Attacker Value
Unknown
CVE-2006-3268
Disclosure Date: June 29, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow users to obtain "random programmatic access" to other email within the same post office.
0
Attacker Value
Unknown
CVE-2002-0341
Disclosure Date: June 25, 2002 (last updated February 22, 2025)
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
0
Attacker Value
Unknown
CVE-2001-1195
Disclosure Date: December 15, 2001 (last updated February 22, 2025)
Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges.
0
Attacker Value
Unknown
CVE-2001-1458
Disclosure Date: October 15, 2001 (last updated February 22, 2025)
Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.
0
Attacker Value
Unknown
CVE-2001-1232
Disclosure Date: August 14, 2001 (last updated February 22, 2025)
GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".
0
Attacker Value
Unknown
CVE-2001-1231
Disclosure Date: August 14, 2001 (last updated February 22, 2025)
GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.
0
Attacker Value
Unknown
CVE-2001-1233
Disclosure Date: August 14, 2001 (last updated February 22, 2025)
Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.
0