Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown
CVE-2010-4325
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Buffer overflow in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP2 allows remote attackers to execute arbitrary code via a crafted TZID variable in a VCALENDAR message.
0
Attacker Value
Unknown
CVE-2010-4326
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Multiple buffer overflows in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via variables in a VCALENDAR message, as demonstrated by a long (1) REQUEST-STATUS, (2) TZNAME, (3) COMMENT, or (4) RRULE variable in this message.
0
Attacker Value
Unknown
CVE-2007-3571
Disclosure Date: July 05, 2007 (last updated October 04, 2023)
The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.
0
Attacker Value
Unknown
CVE-2006-3268
Disclosure Date: June 29, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow users to obtain "random programmatic access" to other email within the same post office.
0
Attacker Value
Unknown
CVE-2005-2620
Disclosure Date: August 17, 2005 (last updated February 22, 2025)
grpWise.exe for Novell GroupWise client 5.5 through 6.5.2 stores the password in plaintext in memory, which allows attackers to obtain the password using a debugger or another mechanism to read process memory.
0
Attacker Value
Unknown
CVE-2005-2276
Disclosure Date: July 26, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "jAvascript" in an IMG tag.
0
Attacker Value
Unknown
CVE-2005-0296
Disclosure Date: January 17, 2005 (last updated February 22, 2025)
NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page. NOTE: the vendor has disputed this issue
0
Attacker Value
Unknown
CVE-2002-1088
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.
0
Attacker Value
Unknown
CVE-2002-0303
Disclosure Date: May 31, 2002 (last updated February 22, 2025)
GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.
0
Attacker Value
Unknown
CVE-2001-1195
Disclosure Date: December 15, 2001 (last updated February 22, 2025)
Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges.
0