Lucene search

K
cve[email protected]CVE-2011-4189
HistoryMar 02, 2012 - 10:55 p.m.

CVE-2011-4189

2012-03-0222:55:01
CWE-94
web.nvd.nist.gov
112
cve-2011-4189
novell groupwise
remote code execution
denial of service
heap memory corruption
application crash
nab file

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8 High

AI Score

Confidence

High

0.201 Low

EPSS

Percentile

96.4%

The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via a long e-mail address in an Address Book (aka .NAB) file.

Affected configurations

NVD
Node
novellgroupwiseMatch8.0
OR
novellgroupwiseMatch8.0hp1
OR
novellgroupwiseMatch8.0hp2
OR
novellgroupwiseMatch8.0sp1
OR
novellgroupwiseMatch8.0.1
OR
novellgroupwiseMatch8.0.2
OR
novellgroupwiseMatch8.0.2hp1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8 High

AI Score

Confidence

High

0.201 Low

EPSS

Percentile

96.4%