peter bassill · operator
$ cve CVE-2012-0439 JSON

CVE-2012-0439 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 39.2% (pctl 99)

Patch early

A public exploit exists.

Description

An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS39.18% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2013-02-24
Last modified2026-06-16

Affected (1)

VendorProduct
novellgroupwise

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD