CVE-2011-3179

Novell GroupWise Messenger < 2.0.4 and Messenger 2.1-2.2 - Unauthenticated Arbitrary Memory Read via Crafted Command

Title source: llm
STIX 2.1

Description

The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.04 and earlier, allows remote attackers to read from arbitrary memory locations via a crafted command.

References (2)

Core 2
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=712158

Scores

EPSS 0.0093
EPSS Percentile 76.3%

Details

CWE
CWE-200
Status published
Products (8)
novell/groupwise_messenger 1.0.6
novell/groupwise_messenger 2.0
novell/groupwise_messenger 2.0.1
novell/groupwise_messenger 2.0.2
novell/groupwise_messenger 2.0.3
novell/groupwise_messenger < 2.0.4
novell/messenger 2.1
novell/messenger 2.2.0
Published Dec 08, 2011
Tracked Since Feb 18, 2026