← Vulnerability feed

Vulnerability record · CVE-2009-1636 · published 26 May 2009

CVE-2009-1636: Novell groupwise memory buffer overflow vulnerability

Novell · Groupwise

Multiple buffer overflows in the Internet Agent (aka GWIA) component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to execute arbitrary code via (1) a crafted e-mail address in an SMTP session or (2) an SMTP command.

10.0 CVSS 2.0 High EPSS 8.4% · top 5.2% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
8.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in the Internet Agent (aka GWIA) component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to execute arbitrary code via (1) a crafted e-mail address in an SMTP session or (2) an SMTP command.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://osvdb.org/54644
http://osvdb.org/54645
http://secunia.com/advisories/35177 Vendor Advisory
http://www.novell.com/support/viewContent.do?externalId=7003272&sliceId=1
http://www.novell.com/support/viewContent.do?externalId=7003273&sliceId=1 Vendor Advisory
http://www.securityfocus.com/archive/1/503724/100/0/threaded
http://www.securityfocus.com/bid/35064
http://www.securityfocus.com/bid/35065
http://www.securitytracker.com/id?1022276
http://www.vupen.com/english/advisories/2009/1393 Vendor Advisory
http://www.vupen.com/exploits/Novell_GroupWise_GWIA_Email_Address_Remote_Buffer_Overflow_Exploit_1393141.php Vendor Advisory
http://www.vupen.com/exploits/Novell_GroupWise_GWIA_SMTP_Command_Remote_Buffer_Overflow_PoC_Exploit_1393140.php Vendor Advisory
https://bugzilla.novell.com/show_bug.cgi?id=478892
https://bugzilla.novell.com/show_bug.cgi?id=482914
https://exchange.xforce.ibmcloud.com/vulnerabilities/50692
https://exchange.xforce.ibmcloud.com/vulnerabilities/50693
http://osvdb.org/54644
http://osvdb.org/54645
http://secunia.com/advisories/35177 Vendor Advisory
http://www.novell.com/support/viewContent.do?externalId=7003272&sliceId=1
http://www.novell.com/support/viewContent.do?externalId=7003273&sliceId=1 Vendor Advisory
http://www.securityfocus.com/archive/1/503724/100/0/threaded
http://www.securityfocus.com/bid/35064
http://www.securityfocus.com/bid/35065
http://www.securitytracker.com/id?1022276
http://www.vupen.com/english/advisories/2009/1393 Vendor Advisory
http://www.vupen.com/exploits/Novell_GroupWise_GWIA_Email_Address_Remote_Buffer_Overflow_Exploit_1393141.php Vendor Advisory
http://www.vupen.com/exploits/Novell_GroupWise_GWIA_SMTP_Command_Remote_Buffer_Overflow_PoC_Exploit_1393140.php Vendor Advisory
https://bugzilla.novell.com/show_bug.cgi?id=478892
https://bugzilla.novell.com/show_bug.cgi?id=482914
https://exchange.xforce.ibmcloud.com/vulnerabilities/50692
https://exchange.xforce.ibmcloud.com/vulnerabilities/50693

Track CVE-2009-1636 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-0610Novell groupwise vulnerabilityThe client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or…EPSS 5.5%10.0CVE-2013-0804Novell groupwise os command injection vulnerabilityThe client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of se…EPSS 12%10.0CVE-2012-0417Novell groupwise vulnerabilityInteger overflow in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attack…EPSS 5.5%10.0CVE-2012-0271Novell groupwise vulnerabilityInteger overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before …EPSS 17%10.0CVE-2011-0333Novell groupwise memory buffer overflow vulnerabilityHeap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 b…EPSS 6.1%10.0CVE-2011-0334Novell groupwise memory buffer overflow vulnerabilityStack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbi…EPSS 4.8%10.0CVE-2011-2662Novell groupwise vulnerabilityInteger signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via …EPSS 4.1%10.0CVE-2011-2663Novell groupwise memory buffer overflow vulnerabilityArray index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a craft…EPSS 5.4%

Source: NIST National Vulnerability Database (record CVE-2009-1636), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.