CVE-2016-5762: Novell Groupwise

Critical severity, CVSS 9.8. EPSS: 5.7% chance of exploitation in the next 30 days.

Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a heap-based buffer overflow.

Affected products

  • Novell Groupwise: up to and including 2012; version 2014 only

Published 2017-04-20. Last modified 2026-06-17.