Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-14932 compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.… Squirrelmail Mitigation only Fix from $2,3002020-06-20 HIGH 8.8 CVE-2020-14933 compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor dispute… Squirrelmail Mitigation only Fix from $1,9502020-06-20 HIGH 7.5 CVE-2012-5623 Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords. Change Passwd Mitigation only Fix from $1,9502020-02-13 HIGH 8.8 CVE-2017-7692EPSS 32% SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mis… Squirrelmail No fix yet Fix from $1,9502017-04-20 MEDIUM 6.8 CVE-2009-1381 The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and… Imap General.php No fix yet Fix from $1,6002009-05-22 MEDIUM 6.5 CVE-2009-0030 A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to acce… Squirrelmail Mitigation only Fix from $1,6002009-01-21 MEDIUM 5.0 CVE-2008-3663 Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests a… Squirrelmail Mitigation only Fix from $1,6002008-09-24 MEDIUM 6.8 CVE-2007-6348 SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introdu… Squirrelmail Mitigation only Fix from $1,6002007-12-14 MEDIUM 5.5 CVE-2006-4169 Multiple directory traversal vulnerabilities in the G/PGP (GPG) Plugin 2.0, and 2.1dev before 20070614, for Squirrelmail allow remote authenticated u… Gpg Plugin Mitigation only Fix from $1,6002007-07-15 HIGH 7.5 CVE-2007-3636 Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecif… Gpg Plugin No fix yet Fix from $1,9502007-07-10 MEDIUM 6.8 CVE-2006-6142 Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML… Squirrelmail Mitigation only Fix from $1,6002006-12-05