VendorsDan Cahillnulllogic_groupware1.2.7
Vulnerabilities

Dan Cahill Nulllogic Groupware 1.2.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2009-2356
Multiple stack-based buffer overflows in the pgsqlQuery function in NullLogic Groupware 1.2.7, when PostgreSQL is used, might allow remote attackers to execute arbitrary code via input to the (1) POP3, (2) SMTP, or (3) web component that triggers a long SQL query.
Published 2009-07-07 · Modified
9.3EPSS 0.039
CVE-2009-2355
The forum module in NullLogic Groupware 1.2.7 allows remote authenticated users to cause a denial of service (application crash) by specifying (1) an empty string or (2) a non-numeric string when selecting a forum, related to the fmessagelist function.
Published 2009-07-07 · Modified
4.0EPSS 0.011