Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Squirrelmail MEDIUM 5.0
CVE-2006-0377

CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the m…

Patch available
Fix from $1,600 2006-02-24
Gpg Plugin HIGH 9.3
CVE-2005-1924EPSS 10%

The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharacters in (1…

Fix: after 2.1
Fix from $1,950 2005-12-31
S Mime Plugin HIGH 7.5
CVE-2005-0239

viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the …

Patch available
Fix from $1,950 2005-05-02
Vacation Plugin HIGH 7.2
CVE-2005-0183

ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters in a comma…

Fix: after 0.15
Fix from $1,950 2005-05-02
Squirrelmail HIGH 7.5
CVE-2005-0152

PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."

Patch available
Fix from $1,950 2005-02-02
Squirrelmail MEDIUM 5.0
CVE-2005-0075

prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via cu…

Patch available
Fix from $1,600 2005-01-29
Squirrelmail HIGH 7.5
CVE-2005-0103

PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifyin…

Patch available
Fix from $1,950 2005-01-24
Squirrelmail MEDIUM 5.8
CVE-2003-0160

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal info…

Fix: after 1.2.11
Fix from $1,600 2003-04-02
Squirrelmail HIGH 7.5
CVE-2002-1648

Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via …

Patch available
Fix from $1,950 2002-12-31
Squirrelmail HIGH 7.5
CVE-2002-1650

The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modified sqspel…

Patch available
Fix from $1,950 2002-12-31
Squirrelmail MEDIUM 6.8
CVE-2002-1341

Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HT…

Patch available
Fix from $1,600 2002-12-18
Squirrelmail HIGH 7.5
CVE-2002-1131EPSS 26%

Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbo…

Fix: after 1.2.7
Fix from $1,950 2002-10-04
Squirrelmail MEDIUM 5.0
CVE-2002-1132

SquirrelMail 1.2.7 and earlier allows remote attackers to determine the absolute pathname of the options.php script via a malformed optpage file argu…

Fix: after 1.2.7
Fix from $1,600 2002-10-04
Squirrelmail HIGH 10.0
CVE-2002-0516EPSS 11%

SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.

Patch available
Fix from $1,950 2002-08-12
Squirrelmail HIGH 7.5
CVE-2001-1159

load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote a…

Patch available
Fix from $1,950 2001-07-02