An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method.
2013-02-24T04:37:19.907
2025-04-11T00:51:21.963
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | novell | groupwise | 8.0 | Yes |
| Application | novell | groupwise | 8.00 | Yes |
| Application | novell | groupwise | 8.00 | Yes |
| Application | novell | groupwise | 8.00 | Yes |
| Application | novell | groupwise | 8.01 | Yes |
| Application | novell | groupwise | 8.01 | Yes |
| Application | novell | groupwise | 8.02 | Yes |
| Application | novell | groupwise | 8.02 | Yes |
| Application | novell | groupwise | 8.02 | Yes |
| Application | novell | groupwise | 8.02 | Yes |
| Application | novell | groupwise | 8.03 | Yes |
| Application | novell | groupwise | 8.03 | Yes |
| Application | novell | groupwise | 2012 | Yes |
| Application | novell | groupwise | 2012 | Yes |