Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-14932
compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.…
Squirrelmail
Mitigation only
HIGH 8.8
CVE-2020-14933
compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor dispute…
Squirrelmail
Mitigation only
HIGH 7.5
CVE-2012-5623
Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.
Change Passwd
Mitigation only
MEDIUM 6.1
CVE-2019-12970
XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in…
Squirrelmail
after 1.5.2
MEDIUM 6.1
CVE-2018-14950
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.
Squirrelmail
after 1.4.22
MEDIUM 6.1
CVE-2018-14951
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.
Squirrelmail
after 1.4.22
MEDIUM 6.1
CVE-2018-14952
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack.
Squirrelmail
after 1.4.22
MEDIUM 6.1
CVE-2018-14953
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.
Squirrelmail
after 1.4.22
MEDIUM 6.1
CVE-2018-14954
The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.
Squirrelmail
after 1.4.22
MEDIUM 6.1
CVE-2018-14955
The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).
Squirrelmail
after 1.4.22
HIGH 8.8
CVE-2017-7692EPSS 32%
SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mis…
Squirrelmail
No fix yet
MEDIUM 6.8
CVE-2011-2753
Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of …
Squirrelmail
after 1.4.21
MEDIUM 5.8
CVE-2011-2752
CRLF injection vulnerability in SquirrelMail 1.4.21 and earlier allows remote attackers to modify or add preference values via a \n (newline) charact…
Squirrelmail
after 1.4.21
MEDIUM 5.0
CVE-2010-2813
functions/imap_general.php in SquirrelMail before 1.4.21 does not properly handle 8-bit characters in passwords, which allows remote attackers to cau…
Squirrelmail
after 1.4.20
MEDIUM 6.8
CVE-2009-2964
Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hija…
Squirrelmail
after 1.4.19
MEDIUM 6.8
CVE-2009-1381
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and…
Imap General.php
No fix yet
MEDIUM 6.8
CVE-2009-1579
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbit…
Squirrelmail
after 1.4.17
MEDIUM 5.8
CVE-2009-1580
Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.
Squirrelmail
after 1.4.17
MEDIUM 6.5
CVE-2009-0030
A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to acce…
Squirrelmail
Mitigation only
MEDIUM 5.0
CVE-2008-3663
Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests a…
Squirrelmail
Mitigation only
MEDIUM 6.8
CVE-2007-6348
SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introdu…
Squirrelmail
Mitigation only
HIGH 7.5
CVE-2007-3778
The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacte…
Gpg Plugin
Patch available
MEDIUM 5.5
CVE-2006-4169
Multiple directory traversal vulnerabilities in the G/PGP (GPG) Plugin 2.0, and 2.1dev before 20070614, for Squirrelmail allow remote authenticated u…
Gpg Plugin
Mitigation only
HIGH 7.5
CVE-2007-3636
Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecif…
Gpg Plugin
No fix yet
MEDIUM 6.5
CVE-2007-3634
Unspecified vulnerability in the G/PGP (GPG) Plugin 2.0 for Squirrelmail 1.4.10a allows remote authenticated users to execute arbitrary commands via …
Gpg Plugin
Patch available
HIGH 7.5
CVE-2007-2631
Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actions as arb…
Squirrelmail
after 1.4.8.4fc6
MEDIUM 5.0
CVE-2007-2589
Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 through 1.4.9a allows remote attackers to send e-mails from arbi…
Squirrelmail
Patch available
MEDIUM 6.8
CVE-2006-6142
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML…
Squirrelmail
Mitigation only
MEDIUM 6.4
CVE-2006-4019EPSS 10%
Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variab…
Squirrelmail
Patch available
HIGH 7.5
CVE-2006-2842EPSS 47%
PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gp…
Squirrelmail
after 1.4.6