Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zimbra Collaboration Suite MEDIUM 6.1
CVE-2020-18985

An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their c…

Mitigation only
Fix from $1,600 2021-12-15
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2020-13653

An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable…

Fix: 8.8.15+
Fix from $1,600 2020-07-02
Zimbra Collaboration Suite HIGH 8.0
CVE-2020-12846

Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is potential abuse of /service/uplo…

Fix: 8.8.15+
Fix from $1,950 2020-06-03
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2020-7796 KEVEPSS 84%

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

Fix: 8.8.15+
Fix from $2,300 2020-02-18
Zimbra Collaboration Suite MEDIUM 5.3
CVE-2020-8633

An issue was discovered in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. When grantors revoked a shared calendar in Outlook, the calendar s…

Fix: 8.8.15+
Fix from $1,600 2020-02-18
Zimbra Collaboration Server CRITICAL 9.8
CVE-2014-8563

Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.

Fix: 8.0.9+
Fix from $2,300 2020-01-27
Zimbra Collaboration Server MEDIUM 6.1
CVE-2014-5500

Synacor Zimbra Collaboration before 8.0.8 has XSS.

Fix: 8.0.8+
Fix from $1,600 2020-01-27
Zimbra Collaboration Server MEDIUM 5.4
CVE-2015-2249

Zimbra Collaboration before 8.6.0 patch5 has XSS.

Fix: after 8.5.1
Fix from $1,600 2020-01-27
Zimbra Collaboration Server MEDIUM 5.4
CVE-2019-11318

Zimbra Collaboration before 8.8.12 Patch 1 has persistent XSS.

Fix: after 8.8.12
Fix from $1,600 2020-01-27
Zimbra Collaboration Server MEDIUM 6.1
CVE-2015-2230

Synacor Zimbra Collaboration Server 8.x before 8.7.0 has Reflected XSS in admin console.

Fix: 8.7.0+
Fix from $1,600 2019-05-30
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2015-7609

Synacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra.

No fix yet
Fix from $1,600 2019-05-30
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2018-14425

There is a Persistent XSS vulnerability in the briefcase component of Synacor Zimbra Collaboration Suite (ZCS) Zimbra Web Client (ZWC) 8.8.8 before 8…

Fix: 8.8.8+
Fix from $1,600 2019-05-30
Zimbra Collaboration Suite MEDIUM 5.3
CVE-2018-15131

An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, a…

Fix: 8.7.11 / 8.8.8+
Fix from $1,600 2019-05-30
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2018-20160

ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XX…

Fix: 8.7.11 / 8.8.9+
Fix from $2,300 2019-05-29
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2019-6980

Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.

Fix: 8.7.11 / 8.8.9+
Fix from $2,300 2019-05-29
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2019-9670 KEVEPSS 100%

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstr…

Fix: 8.7.11+
Fix from $2,300 2019-05-29
Zimbra Collaboration Suite MEDIUM 6.5
CVE-2019-6981

Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component.

Fix: 8.7.11 / 8.8.9+
Fix from $1,600 2019-05-29
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2018-18631

mailboxd component in Synacor Zimbra Collaboration Suite 8.6, 8.7 before 8.7.11 Patch 7, and 8.8 before 8.8.10 Patch 2 has Persistent XSS.

Fix: 8.7.11 / 8.8.9+
Fix from $1,600 2019-05-29
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2018-14013EPSS 7%

Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.

Fix: 8.7.11 / 8.8.9+
Fix from $1,600 2019-05-29
Zimbra Collaboration Suite HIGH 7.5
CVE-2019-9621 KEVEPSS 81%

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows S…

Fix: 8.6.0 / 8.7.11+
Fix from $1,950 2019-04-30
Zimbra Collaboration Suite MEDIUM 5.3
CVE-2018-17938

Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.

Fix: 8.8.10+
Fix from $1,600 2018-10-03
Zimbra Collaboration Suite HIGH 8.8
CVE-2015-7610

Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 …

Fix: after 8.8.8
Fix from $1,950 2018-05-30
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2018-10939

Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.

Fix: after 8.8.8
Fix from $1,600 2018-05-30
Zimbra Collaboration Suite MEDIUM 6.5
CVE-2018-10951

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read acces…

Fix: 8.8.8+
Fix from $1,600 2018-05-10
Zimbra Collaboration Suite MEDIUM 5.3
CVE-2018-10949

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy bet…

Fix: 8.8.8+
Fix from $1,600 2018-05-10
Zimbra Collaboration Suite MEDIUM 5.3
CVE-2018-10950

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through V…

Fix: 8.7.11 / 8.8.8+
Fix from $1,600 2018-05-10
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2018-6882 KEVEPSS 25%

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 a…

Fix: 8.7.0+
Fix from $1,600 2018-03-27
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2017-17703

Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS.

Fix: 8.8.3+
Fix from $1,600 2018-02-04
Zimbra Collaboration Suite MEDIUM 5.4
CVE-2017-8783

Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS.

Fix: 8.7.10+
Fix from $1,600 2018-02-04
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2017-6813

A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations.

Fix: after 8.7.5
Fix from $2,300 2017-05-23