Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Squirrelmail CRITICAL 9.8
CVE-2020-14932

compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.…

Mitigation only
Fix from $2,300 2020-06-20
Squirrelmail HIGH 8.8
CVE-2020-14933

compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor dispute…

Mitigation only
Fix from $1,950 2020-06-20
Change Passwd HIGH 7.5
CVE-2012-5623

Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.

Mitigation only
Fix from $1,950 2020-02-13
Squirrelmail MEDIUM 6.1
CVE-2019-12970

XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in…

Fix: after 1.5.2
Fix from $1,600 2019-07-01
Squirrelmail MEDIUM 6.1
CVE-2018-14950

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.

Fix: after 1.4.22
Fix from $1,600 2018-08-05
Squirrelmail MEDIUM 6.1
CVE-2018-14951

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.

Fix: after 1.4.22
Fix from $1,600 2018-08-05
Squirrelmail MEDIUM 6.1
CVE-2018-14952

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack.

Fix: after 1.4.22
Fix from $1,600 2018-08-05
Squirrelmail MEDIUM 6.1
CVE-2018-14953

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

Fix: after 1.4.22
Fix from $1,600 2018-08-05
Squirrelmail MEDIUM 6.1
CVE-2018-14954

The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.

Fix: after 1.4.22
Fix from $1,600 2018-08-05
Squirrelmail MEDIUM 6.1
CVE-2018-14955

The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).

Fix: after 1.4.22
Fix from $1,600 2018-08-05
Squirrelmail HIGH 8.8
CVE-2017-7692EPSS 32%

SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mis…

No fix yet
Fix from $1,950 2017-04-20
Squirrelmail MEDIUM 6.8
CVE-2011-2753

Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of …

Fix: after 1.4.21
Fix from $1,600 2011-07-17
Squirrelmail MEDIUM 5.8
CVE-2011-2752

CRLF injection vulnerability in SquirrelMail 1.4.21 and earlier allows remote attackers to modify or add preference values via a \n (newline) charact…

Fix: after 1.4.21
Fix from $1,600 2011-07-17
Squirrelmail MEDIUM 5.0
CVE-2010-2813

functions/imap_general.php in SquirrelMail before 1.4.21 does not properly handle 8-bit characters in passwords, which allows remote attackers to cau…

Fix: after 1.4.20
Fix from $1,600 2010-08-19
Squirrelmail MEDIUM 6.8
CVE-2009-2964

Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hija…

Fix: after 1.4.19
Fix from $1,600 2009-08-25
Imap General.php MEDIUM 6.8
CVE-2009-1381

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and…

No fix yet
Fix from $1,600 2009-05-22
Squirrelmail MEDIUM 6.8
CVE-2009-1579

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbit…

Fix: after 1.4.17
Fix from $1,600 2009-05-14
Squirrelmail MEDIUM 5.8
CVE-2009-1580

Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.

Fix: after 1.4.17
Fix from $1,600 2009-05-14
Squirrelmail MEDIUM 6.5
CVE-2009-0030

A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to acce…

Mitigation only
Fix from $1,600 2009-01-21
Squirrelmail MEDIUM 5.0
CVE-2008-3663

Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests a…

Mitigation only
Fix from $1,600 2008-09-24
Squirrelmail MEDIUM 6.8
CVE-2007-6348

SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introdu…

Mitigation only
Fix from $1,600 2007-12-14
Gpg Plugin HIGH 7.5
CVE-2007-3778

The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacte…

Patch available
Fix from $1,950 2007-07-15
Gpg Plugin MEDIUM 5.5
CVE-2006-4169

Multiple directory traversal vulnerabilities in the G/PGP (GPG) Plugin 2.0, and 2.1dev before 20070614, for Squirrelmail allow remote authenticated u…

Mitigation only
Fix from $1,600 2007-07-15
Gpg Plugin HIGH 7.5
CVE-2007-3636

Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecif…

No fix yet
Fix from $1,950 2007-07-10
Gpg Plugin MEDIUM 6.5
CVE-2007-3634

Unspecified vulnerability in the G/PGP (GPG) Plugin 2.0 for Squirrelmail 1.4.10a allows remote authenticated users to execute arbitrary commands via …

Patch available
Fix from $1,600 2007-07-10
Squirrelmail HIGH 7.5
CVE-2007-2631

Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actions as arb…

Fix: after 1.4.8.4fc6
Fix from $1,950 2007-05-13
Squirrelmail MEDIUM 5.0
CVE-2007-2589

Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 through 1.4.9a allows remote attackers to send e-mails from arbi…

Patch available
Fix from $1,600 2007-05-11
Squirrelmail MEDIUM 6.8
CVE-2006-6142

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML…

Mitigation only
Fix from $1,600 2006-12-05
Squirrelmail MEDIUM 6.4
CVE-2006-4019EPSS 10%

Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variab…

Patch available
Fix from $1,600 2006-08-11
Squirrelmail HIGH 7.5
CVE-2006-2842EPSS 47%

PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gp…

Fix: after 1.4.6
Fix from $1,950 2006-06-06