Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webmail HIGH 8.8
CVE-2015-2181

Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via…

Fix: 1.1.0+
Fix from $1,950 2017-01-30
Webmail MEDIUM 6.1
CVE-2016-4552

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the hre…

No fix yet
Fix from $1,600 2016-12-20
Webmail HIGH 7.5
CVE-2016-9920EPSS 6%

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does…

Fix: after 1.1.6
Fix from $1,950 2016-12-08
Roundcube Webmail MEDIUM 6.5
CVE-2015-8794

Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authentic…

Fix: after 1.0.5
Fix from $1,600 2016-01-29
Webmail MEDIUM 6.1
CVE-2015-8793

Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to in…

Fix: after 1.0.5
Fix from $1,600 2016-01-29
Roundcube Webmail HIGH 7.5
CVE-2015-8770EPSS 22%

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4…

Fix: after 1.0.7
Fix from $1,950 2016-01-29
Webmail MEDIUM 6.8
CVE-2014-9587

Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of u…

Fix: after 1.0.3
Fix from $1,600 2015-01-15
Webmail MEDIUM 5.0
CVE-2013-1904

Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to …

Fix: after 0.7.2
Fix from $1,600 2014-02-08
Webmail HIGH 7.5
CVE-2013-6172

steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _…

Fix: after 0.8.6
Fix from $1,950 2013-11-05
Webmail MEDIUM 5.0
CVE-2011-4078

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an a…

Fix: after 0.5.4
Fix from $1,600 2011-11-03
Webmail MEDIUM 5.5
CVE-2011-1492

steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Sty…

Fix: after 0.5
Fix from $1,600 2011-04-08
Webmail MEDIUM 5.0
CVE-2010-0464

Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it …

Fix: after 0.3.1
Fix from $1,600 2010-01-29
Webmail MEDIUM 6.8
CVE-2009-4076

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspec…

Fix: after 0.2.2
Fix from $1,600 2009-11-25
Webmail MEDIUM 6.8
CVE-2009-4077

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspec…

Fix: after 0.2.2
Fix from $1,600 2009-11-25
Webmail HIGH 10.0
CVE-2008-5619EPSS 59%

html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, …

Patch available
Fix from $1,950 2008-12-17
Webmail HIGH 7.8
CVE-2008-5620

RoundCube Webmail (roundcubemail) before 0.2-beta allows remote attackers to cause a denial of service (memory consumption) via crafted size paramete…

Fix: after 0.2
Fix from $1,950 2008-12-17
Webmail MEDIUM 5.0
CVE-2005-4368

roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of th…

Mitigation only
Fix from $1,600 2005-12-20