← All CVEs

CVE-2008-2703

high · 10

Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow remote attackers to execute arbitrary code via "spoofed server responses" that contain a long string after the NM_A_SZ_TRANSACTION_ID field name.

10
CVSS
61.1%
EPSS (exploit prob.)
99th
EPSS percentile
2008-06-13
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
novellgroupwise_messenger2.0
novellgroupwise_messenger2.0.2
novellgroupwise_messenger2.0.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-2703