Groupwise

Vendor:

First CVE: Dec 19, 1999 · Active for 26 years

74
Total CVEs
More Total CVEs than 99% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Groupwise over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 1999
26 years ago
Most Recent CVE
Apr 20, 2017
3,385 days ago

CVE Severity & Scoring

Groupwise74 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (5.4%)
Unknown70 (94.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (5.4%)
High0 (0.0%)
Unknown70 (94.6%)
User Interaction
None1 (1.4%)
Unknown70 (94.6%)
Required3 (4.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (5.4%)
Unknown70 (94.6%)

Top CVEs

Signals from CVEs in this product scope (74 CVEs).

74 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer
Feb 24, 20139.369NOYES
Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrar
Sep 28, 20125.052NOYES
Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI.
May 2, 20089.351NOYES
Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attacker
Sep 19, 201210.050NOYES
Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a
Jan 31, 201110.044NOYES
The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer derefe
Feb 24, 201310.041NOYES
Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote att
Jan 28, 20119.040NOYES
Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agent components in Novell GroupWise before 8.02HP allow remote attackers to read ar
Jan 31, 20115.039NOYES
Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitra
Feb 3, 200910.039NOYES
The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) vi
Mar 2, 20127.537NOYES

Exploit Exposure

Signals from CVEs in this product scope (74 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
17 CVEs
23.0% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (74 CVEs).

Media Mentions

Signals from CVEs in this product scope (74 CVEs).

Top CNAs Publishing CVEs For Groupwise

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0367.711.1%03
8.0.217.511.6%01
8.02117.512.4%04
8.0.1108.310.4%04
8.01117.412.2%04
8.00126.810.5%03
8.0417.36.6%011
7.0.4137.28.2%04
7.0.3.129415.05.0%01
7.0.3187.07.3%05
7.03136.04.8%03
7.02x65.82.8%01
7.0.2147.68.0%04
7.0245.95.9%01
7.0.198.410.2%03
7.01126.04.6%02
7.0.065.73.7%02
7.0326.57.4%09
6.5_sp6_update_113.51.1%00
6.5.7157.27.9%05