Groupwise
Vendor:
First CVE: Dec 19, 1999 · Active for 26 years
74
Total CVEs
More Total CVEs than 99% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Groupwise over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 1999
26 years ago
Most Recent CVE
Apr 20, 2017
3,385 days ago
CVE Severity & Scoring
Groupwise74 CVEs
58%
39%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (5.4%)
Unknown70 (94.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (5.4%)
High0 (0.0%)
Unknown70 (94.6%)
User Interaction
None1 (1.4%)
Unknown70 (94.6%)
Required3 (4.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (5.4%)
Unknown70 (94.6%)
Top CVEs
Signals from CVEs in this product scope (74 CVEs).
74 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0439HIGH An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer | Feb 24, 2013 | 9.3 | 69 | NO | YES |
CVE-2012-0419MEDIUM Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrar | Sep 28, 2012 | 5.0 | 52 | NO | YES |
CVE-2008-2069HIGH Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI. | May 2, 2008 | 9.3 | 51 | NO | YES |
CVE-2012-0271HIGH Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attacker | Sep 19, 2012 | 10.0 | 50 | NO | YES |
CVE-2010-4711HIGH Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a | Jan 31, 2011 | 10.0 | 44 | NO | YES |
CVE-2013-0804HIGH The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer derefe | Feb 24, 2013 | 10.0 | 41 | NO | YES |
CVE-2010-2777HIGH Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote att | Jan 28, 2011 | 9.0 | 40 | NO | YES |
CVE-2010-4715MEDIUM Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agent components in Novell GroupWise before 8.02HP allow remote attackers to read ar | Jan 31, 2011 | 5.0 | 39 | NO | YES |
CVE-2009-0410HIGH Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitra | Feb 3, 2009 | 10.0 | 39 | NO | YES |
CVE-2011-4189HIGH The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) vi | Mar 2, 2012 | 7.5 | 37 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (74 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
17 CVEs
23.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (74 CVEs).
Media Mentions
Signals from CVEs in this product scope (74 CVEs).
Top CNAs Publishing CVEs For Groupwise
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.03 | 6 | 7.7 | 11.1% | 0 | 3 |
| 8.0.2 | 1 | 7.5 | 11.6% | 0 | 1 |
| 8.02 | 11 | 7.5 | 12.4% | 0 | 4 |
| 8.0.1 | 10 | 8.3 | 10.4% | 0 | 4 |
| 8.01 | 11 | 7.4 | 12.2% | 0 | 4 |
| 8.00 | 12 | 6.8 | 10.5% | 0 | 3 |
| 8.0 | 41 | 7.3 | 6.6% | 0 | 11 |
| 7.0.4 | 13 | 7.2 | 8.2% | 0 | 4 |
| 7.0.3.1294 | 1 | 5.0 | 5.0% | 0 | 1 |
| 7.0.3 | 18 | 7.0 | 7.3% | 0 | 5 |
| 7.03 | 13 | 6.0 | 4.8% | 0 | 3 |
| 7.02x | 6 | 5.8 | 2.8% | 0 | 1 |
| 7.0.2 | 14 | 7.6 | 8.0% | 0 | 4 |
| 7.02 | 4 | 5.9 | 5.9% | 0 | 1 |
| 7.0.1 | 9 | 8.4 | 10.2% | 0 | 3 |
| 7.01 | 12 | 6.0 | 4.6% | 0 | 2 |
| 7.0.0 | 6 | 5.7 | 3.7% | 0 | 2 |
| 7.0 | 32 | 6.5 | 7.4% | 0 | 9 |
| 6.5_sp6_update_1 | 1 | 3.5 | 1.1% | 0 | 0 |
| 6.5.7 | 15 | 7.2 | 7.9% | 0 | 5 |