Lucene search

K
cve[email protected]CVE-2012-0439
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-0439

2022-10-0316:15:41
CWE-94
web.nvd.nist.gov
31
cve-2012-0439
activex
novell groupwise
remote code execution
security vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.967 High

EPSS

Percentile

99.7%

An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method.

Affected configurations

NVD
Node
novellgroupwiseMatch8.0
OR
novellgroupwiseMatch8.00hp1
OR
novellgroupwiseMatch8.00hp2
OR
novellgroupwiseMatch8.00hp3
OR
novellgroupwiseMatch8.01
OR
novellgroupwiseMatch8.01hp
OR
novellgroupwiseMatch8.02
OR
novellgroupwiseMatch8.02hp1
OR
novellgroupwiseMatch8.02hp2
OR
novellgroupwiseMatch8.02hp3
OR
novellgroupwiseMatch8.03
OR
novellgroupwiseMatch8.03hp1
Node
novellgroupwiseMatch2012
OR
novellgroupwiseMatch2012sp1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.967 High

EPSS

Percentile

99.7%