← Vulnerability feed

Vulnerability record · CVE-2007-6435 · published 18 December 2007

CVE-2007-6435: Novell groupwise memory buffer overflow vulnerability

Novell · Groupwise

Stack-based buffer overflow in Novell GroupWise before 6.5.7, when HTML preview of e-mail is enabled, allows user-assisted remote attackers to execute arbitrary code via a long SRC attribute in an IMG element when forwarding or replying to a crafted e-mail.

9.3 CVSS 2.0 High EPSS 6.6% · top 6.4% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
6.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Novell GroupWise before 6.5.7, when HTML preview of e-mail is enabled, allows user-assisted remote attackers to execute arbitrary code via a long SRC attribute in an IMG element when forwarding or replying to a crafted e-mail.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-6435 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-0610Novell groupwise vulnerabilityThe client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or…EPSS 5.5%10.0CVE-2013-0804Novell groupwise os command injection vulnerabilityThe client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of se…EPSS 12%10.0CVE-2012-0417Novell groupwise vulnerabilityInteger overflow in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attack…EPSS 5.5%10.0CVE-2012-0271Novell groupwise vulnerabilityInteger overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before …EPSS 17%10.0CVE-2011-0333Novell groupwise memory buffer overflow vulnerabilityHeap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 b…EPSS 6.1%10.0CVE-2011-0334Novell groupwise memory buffer overflow vulnerabilityStack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbi…EPSS 4.8%10.0CVE-2011-2662Novell groupwise vulnerabilityInteger signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via …EPSS 4.1%10.0CVE-2011-2663Novell groupwise memory buffer overflow vulnerabilityArray index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a craft…EPSS 5.4%

Source: NIST National Vulnerability Database (record CVE-2007-6435), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.