Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-2171

36
FAUCET Score

CVE-2007-2171 describes a critical stack-based buffer overflow in the base64_decode function of Novell GroupWise WebAccess versions prior to 7.0 SP2. This vulnerability allows unauthenticated remote attackers to execute arbitrary code by sending crafted, long base64 content within an HTTP Basic Authentication request. With a CVSS score of 10.0, this flaw presents a severe risk, enabling complete compromise of confidentiality, integrity, and availability with low attack complexity. While there is no evidence of active exploitation, public exploit code, or significant community discussion, its high CVSS score and EPSS percentile indicate a significant potential threat.

Impacted Technologies

VendorProductVersion(s)CPE
7.0CPE matchmatch criteria
cpe:2.3:a:novell:groupwise:7.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:a:novell:groupwise:7.0:sp1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

10.0HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
24.33%
Probability of exploitation in next 30 days
EPSS Percentile
97.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.2433 is in the 96th percentile among its peer group of 51,551 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

fuji_electricvendor investigatingvia llm_extracted
langgeniusvendor investigatingvia llm_extracted
lizardbytevendor investigatingvia llm_extracted
opensipsvendor investigatingvia llm_extracted

Vendor Advisories (4)

langgeniusllm-langgenius-8011eb7ac87a06fcCRITICAL

Novell GroupWise WebAccess GWINTER.exe Basic Authentication Base64 Decoding Overflow

Apr 18, 2007
lizardbytellm-lizardbyte-00b41b1eb956f81eCRITICAL

Novell GroupWise WebAccess GWINTER.exe Basic Authentication Base64 Decoding Overflow

Apr 18, 2007
opensipsllm-opensips-f2d347d182191130CRITICAL

Novell GroupWise WebAccess GWINTER.exe Basic Authentication Base64 Decoding Overflow

Apr 18, 2007
fuji_electricllm-fuji_electric-8b3fbd3cc3ddc602CRITICAL

Novell GroupWise WebAccess GWINTER.exe Basic Authentication Base64 Decoding Overflow

Apr 18, 2007

References

download.novell.com / Download
Patch
download.novell.com / Download
Patch
secunia.com / advisories/24944
Vendor Advisory
securityreason.com / securityalert/2610
securityfocus.com / archive/1/466212/100/0/threaded
securityfocus.com / bid/23556
securitytracker.com / id
vupen.com / english/advisories/2007/1455
zerodayinitiative.com / advisories/ZDI-07-015.html