Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2025-41066 Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the existence of valid accounts on … Groupware Mitigation only Fix from $1,6002025-12-02 MEDIUM 6.1 CVE-2020-8034 Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vul… Gollem 3.0.13+ Fix from $1,6002020-05-18 MEDIUM 6.1 CVE-2020-8035 The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an… Groupware 5.2.22+ Fix from $1,6002020-05-18 HIGH 8.8 CVE-2019-12095 Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags para… Groupware after 5.2.22 Fix from $1,9502019-10-24 MEDIUM 6.1 CVE-2019-12094 Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= o… Groupware after 5.2.22 Fix from $1,6002019-10-24 HIGH 8.1 CVE-2014-3999 The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN. Horde Ldap 2.0.6+ Fix from $1,9502018-04-10 MEDIUM 5.4 CVE-2017-16906 In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action. Groupware after 5.2.22 Fix from $1,6002017-11-20 MEDIUM 5.4 CVE-2017-16907 In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action. Groupware Patch available Fix from $1,6002017-11-20 MEDIUM 5.4 CVE-2017-16908 In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after c… Groupware Patch available Fix from $1,6002017-11-20 HIGH 7.5 CVE-2017-15235EPSS 6% The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a cra… Groupware No fix yet Fix from $1,9502017-10-11 HIGH 8.1 CVE-2017-14650 A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "convert" uti… Horde Image Api Patch available Fix from $1,9502017-09-21 HIGH 8.8 CVE-2017-9774 Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication. Horde Image Api Mitigation only Fix from $1,9502017-06-21 MEDIUM 5.7 CVE-2017-9773 Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver. Horde Image No fix yet Fix from $1,6002017-06-21 HIGH 8.8 CVE-2017-7413EPSS 40% In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenti… Groupware after 5.2.17 Fix from $1,9502017-04-04 HIGH 7.5 CVE-2017-7414 In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP featur… Groupware Mitigation only Fix from $1,9502017-04-04 MEDIUM 6.1 CVE-2016-5303 Cross-site scripting (XSS) vulnerability in the Horde Text Filter API in Horde Groupware and Horde Groupware Webmail Edition before 5.2.16 allows rem… Groupware Patch available Fix from $1,6002016-12-20 HIGH 7.5 CVE-2014-1691EPSS 43% The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attac… Horde Application Framework after 5.1.0 Fix from $1,9502014-04-01 HIGH 7.5 CVE-2012-0209EPSS 72% Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, cont… Groupware Patch available Fix from $1,9502012-09-25 MEDIUM 6.8 CVE-2010-3694 Cross-site request forgery (CSRF) vulnerability in the Horde Application Framework before 3.3.9 allows remote attackers to hijack the authentication … Horde Application Framework after 3.3.8 Fix from $1,6002010-11-09 MEDIUM 5.0 CVE-2010-1638 The IMP plugin in Horde allows remote attackers to bypass firewall restrictions and use Horde as a proxy to scan internal networks via a crafted requ… Horde Mitigation only Fix from $1,6002010-06-22 MEDIUM 5.0 CVE-2010-0463 Horde IMP 4.3.6 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it … Imp after 4.3.6 Fix from $1,6002010-01-29 HIGH 10.0 CVE-2008-7218 Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-… Groupware Patch available Fix from $1,9502009-09-13 HIGH 10.0 CVE-2008-7219 Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 befo… Groupware Patch available Fix from $1,9502009-09-13 HIGH 9.0 CVE-2008-3650 Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unesc… Groupware Webmail Edition Patch available Fix from $1,9502008-08-13 MEDIUM 6.0 CVE-2008-1284 Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain confi… Groupware after 1.0.5 Fix from $1,6002008-03-11 MEDIUM 5.8 CVE-2007-6018 IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, w… Framework Patch available Fix from $1,6002008-01-11 MEDIUM 5.4 CVE-2007-1679 Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or… Groupware Mitigation only Fix from $1,6002007-03-26 MEDIUM 6.8 CVE-2007-1474 Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local user… Horde Application Framework Patch available Fix from $1,6002007-03-16 MEDIUM 5.1 CVE-2007-0579 Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition before 1.0, and Groupware before 1.0, allows remote attackers … Groupware Patch available Fix from $1,6002007-01-30 HIGH 7.5 CVE-2006-6175 Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to include arbi… Kronolith Patch available Fix from $1,9502006-11-30