Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2015-2181 Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via… Webmail 1.1.0+ Fix from $1,9502017-01-30 MEDIUM 6.1 CVE-2016-4552 Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the hre… Webmail No fix yet Fix from $1,6002016-12-20 HIGH 7.5 CVE-2016-9920EPSS 6% steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does… Webmail after 1.1.6 Fix from $1,9502016-12-08 MEDIUM 6.5 CVE-2015-8794 Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authentic… Roundcube Webmail after 1.0.5 Fix from $1,6002016-01-29 MEDIUM 6.1 CVE-2015-8793 Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to in… Webmail after 1.0.5 Fix from $1,6002016-01-29 HIGH 7.5 CVE-2015-8770EPSS 22% Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4… Roundcube Webmail after 1.0.7 Fix from $1,9502016-01-29 MEDIUM 6.8 CVE-2014-9587 Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of u… Webmail after 1.0.3 Fix from $1,6002015-01-15 MEDIUM 5.0 CVE-2013-1904 Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to … Webmail after 0.7.2 Fix from $1,6002014-02-08 HIGH 7.5 CVE-2013-6172 steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _… Webmail after 0.8.6 Fix from $1,9502013-11-05 MEDIUM 5.0 CVE-2011-4078 include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an a… Webmail after 0.5.4 Fix from $1,6002011-11-03 MEDIUM 5.5 CVE-2011-1492 steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Sty… Webmail after 0.5 Fix from $1,6002011-04-08 MEDIUM 5.0 CVE-2010-0464 Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it … Webmail after 0.3.1 Fix from $1,6002010-01-29 MEDIUM 6.8 CVE-2009-4076 Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspec… Webmail after 0.2.2 Fix from $1,6002009-11-25 MEDIUM 6.8 CVE-2009-4077 Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspec… Webmail after 0.2.2 Fix from $1,6002009-11-25 HIGH 10.0 CVE-2008-5619EPSS 59% html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, … Webmail Patch available Fix from $1,9502008-12-17 HIGH 7.8 CVE-2008-5620 RoundCube Webmail (roundcubemail) before 0.2-beta allows remote attackers to cause a denial of service (memory consumption) via crafted size paramete… Webmail after 0.2 Fix from $1,9502008-12-17 MEDIUM 5.0 CVE-2005-4368 roundcube webmail Alpha, with a default high verbose level ($rcmail_config['debug_level'] = 1), allows remote attackers to obtain the full path of th… Webmail Mitigation only Fix from $1,6002005-12-20