Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ingo H3 MEDIUM 6.5
CVE-2006-5449

procmail in Ingo H3 before 1.1.2 Horde module allows remote authenticated users to execute arbitrary commands via shell metacharacters in the mailbox…

Fix: after 1.1.1
Fix from $1,600 2006-10-23
Horde Application Framework MEDIUM 5.0
CVE-2006-3549

services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, wh…

Patch available
Fix from $1,600 2006-07-13
Horde MEDIUM 6.8
CVE-2006-2195

Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) temp…

Fix: after 3.0.9
Fix from $1,600 2006-06-15
Application Framework HIGH 7.5
CVE-2006-1491EPSS 38%

Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitr…

Patch available
Fix from $1,950 2006-03-29
Horde MEDIUM 5.0
CVE-2006-1260EPSS 12%

Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parameter in services/go.php, which…

Patch available
Fix from $1,600 2006-03-19
Horde MEDIUM 5.8
CVE-2005-3759

Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) g…

Patch available
Fix from $1,600 2005-11-22
Horde HIGH 10.0
CVE-2005-3344EPSS 8%

The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.

Patch available
Fix from $1,950 2005-11-16
Chora MEDIUM 6.8
CVE-2005-1317

Cross-site scripting (XSS) vulnerability in Horde Chora module before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the pa…

Fix: after 1.1
Fix from $1,600 2005-04-25
Imp MEDIUM 6.8
CVE-2004-0584

Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which allows remote attackers to exe…

Patch available
Fix from $1,600 2004-08-06
Horde MEDIUM 6.4
CVE-2003-0728

Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.

Fix: after 2.2.4
Fix from $1,600 2003-10-20
Imp HIGH 7.5
CVE-2003-0025EPSS 28%

Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain …

Patch available
Fix from $1,950 2003-01-17
Imp MEDIUM 5.3
CVE-2002-2024

Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2…

Mitigation only
Fix from $1,600 2002-12-31
Horde HIGH 7.5
CVE-2002-0181

Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal coo…

Patch available
Fix from $1,950 2002-04-22
Imp HIGH 7.5
CVE-2001-1257

Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Java…

Patch available
Fix from $1,950 2001-07-21
Imp MEDIUM 5.0
CVE-2000-0911

IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to se…

Patch available
Fix from $1,600 2000-12-19