Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Squirrelmail CRITICAL 9.8
CVE-2020-14932

compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.…

Mitigation only
Fix from $2,300 2020-06-20
Squirrelmail HIGH 8.8
CVE-2020-14933

compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor dispute…

Mitigation only
Fix from $1,950 2020-06-20
Change Passwd HIGH 7.5
CVE-2012-5623

Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.

Mitigation only
Fix from $1,950 2020-02-13
Squirrelmail HIGH 8.8
CVE-2017-7692EPSS 32%

SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mis…

No fix yet
Fix from $1,950 2017-04-20
Imap General.php MEDIUM 6.8
CVE-2009-1381

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and…

No fix yet
Fix from $1,600 2009-05-22
Squirrelmail MEDIUM 6.5
CVE-2009-0030

A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to acce…

Mitigation only
Fix from $1,600 2009-01-21
Squirrelmail MEDIUM 5.0
CVE-2008-3663

Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests a…

Mitigation only
Fix from $1,600 2008-09-24
Squirrelmail MEDIUM 6.8
CVE-2007-6348

SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introdu…

Mitigation only
Fix from $1,600 2007-12-14
Gpg Plugin MEDIUM 5.5
CVE-2006-4169

Multiple directory traversal vulnerabilities in the G/PGP (GPG) Plugin 2.0, and 2.1dev before 20070614, for Squirrelmail allow remote authenticated u…

Mitigation only
Fix from $1,600 2007-07-15
Gpg Plugin HIGH 7.5
CVE-2007-3636

Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecif…

No fix yet
Fix from $1,950 2007-07-10
Squirrelmail MEDIUM 6.8
CVE-2006-6142

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML…

Mitigation only
Fix from $1,600 2006-12-05