peter bassill · operator
$ cve CVE-2012-0271 JSON

CVE-2012-0271 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 17.2% (pctl 97)

Patch early

A public exploit exists.

Description

Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow, as demonstrated by a request with -1 in the Content-Length HTTP header.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS17.23% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2012-09-19
Last modified2026-06-16

Affected (1)

VendorProduct
novellgroupwise

Public exploits

SourceTitleDate
exploit-dbNovell Groupwise 8.0.2 HP3 and 2012 - Integer Overflow2012-09-17

References

→ the Explorer  ·  watch your stack  ·  NVD