Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Collaboration MEDIUM 6.1
CVE-2022-41351

In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing …

Mitigation only
Fix from $1,600 2022-10-12
Collaboration HIGH 7.8
CVE-2022-41347

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGI…

Patch available
Fix from $1,950 2022-09-26
Collaboration HIGH 7.8
CVE-2022-37393

Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended function…

Patch available
Fix from $1,950 2022-08-16
Collaboration HIGH 7.5
CVE-2022-37041

An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-H…

Patch available
Fix from $1,950 2022-08-12
Collaboration MEDIUM 6.1
CVE-2022-37044

In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onload that are partially sanitis…

Patch available
Fix from $1,600 2022-08-12
Collaboration MEDIUM 5.7
CVE-2022-37043

An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked …

Patch available
Fix from $1,600 2022-08-12
Collaboration CRITICAL 9.8
CVE-2022-32294

Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible i…

Patch available
Fix from $2,300 2022-07-11
Collaboration CRITICAL 9.8
CVE-2021-35209

An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patc…

Fix: 8.8.15+
Fix from $2,300 2021-07-02
Collaboration MEDIUM 6.1
CVE-2021-34807

An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker wo…

Fix: 8.8.15+
Fix from $1,600 2021-07-02
Collaboration MEDIUM 6.1
CVE-2021-35207

An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability exists in the lo…

Fix: 8.8.15+
Fix from $1,600 2021-07-02
Collaboration MEDIUM 5.4
CVE-2021-35208

An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 23. An attacker …

Fix: 8.8.15+
Fix from $1,600 2021-07-02
Collaboration MEDIUM 6.5
CVE-2020-35123

In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store exten…

Fix: 8.8.15+
Fix from $1,600 2020-12-17
Zimbra MEDIUM 6.1
CVE-2020-11737

A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invit…

Mitigation only
Fix from $1,600 2020-05-05
Zm Mailbox MEDIUM 6.5
CVE-2020-10194

cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs fro…

Fix: 8.8.15+
Fix from $1,600 2020-03-20
Zimbra MEDIUM 6.1
CVE-2013-1938

Zimbra 2013 has XSS in aspell.php

Patch available
Fix from $1,600 2020-02-12
Collaboration Server MEDIUM 6.1
CVE-2019-15313

In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability.

Fix: 8.8.15+
Fix from $1,600 2020-01-27
Collaboration Server MEDIUM 6.1
CVE-2019-8945

Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

Fix: after 8.8.11
Fix from $1,600 2020-01-27
Collaboration Server MEDIUM 6.1
CVE-2019-8946

Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

Fix: after 8.8.11
Fix from $1,600 2020-01-27
Collaboration Server MEDIUM 6.1
CVE-2019-8947

Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS.

Fix: after 8.8.11
Fix from $1,600 2020-01-27
Zimbra Collaboration Server MEDIUM 6.1
CVE-2016-5721

Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTM…

Fix: after 8.6.0
Fix from $1,600 2016-08-29
Zimbra Collaboration Server HIGH 8.8
CVE-2015-6541

Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attacke…

Fix: after 8.0.9
Fix from $1,950 2016-04-08
Collaboration Server HIGH 10.0
CVE-2013-7217

Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impact and unspecified vectors, a…

Fix: after 7.2.5
Fix from $1,950 2013-12-26