Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2022-41351 In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing … Collaboration Mitigation only Fix from $1,6002022-10-12 HIGH 7.8 CVE-2022-41347 An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGI… Collaboration Patch available Fix from $1,9502022-09-26 HIGH 7.8 CVE-2022-37393 Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended function… Collaboration Patch available Fix from $1,9502022-08-16 HIGH 7.5 CVE-2022-37041 An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-H… Collaboration Patch available Fix from $1,9502022-08-12 MEDIUM 6.1 CVE-2022-37044 In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onload that are partially sanitis… Collaboration Patch available Fix from $1,6002022-08-12 MEDIUM 5.7 CVE-2022-37043 An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked … Collaboration Patch available Fix from $1,6002022-08-12 CRITICAL 9.8 CVE-2022-32294 Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible i… Collaboration Patch available Fix from $2,3002022-07-11 CRITICAL 9.8 CVE-2021-35209 An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patc… Collaboration 8.8.15+ Fix from $2,3002021-07-02 MEDIUM 6.1 CVE-2021-34807 An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker wo… Collaboration 8.8.15+ Fix from $1,6002021-07-02 MEDIUM 6.1 CVE-2021-35207 An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability exists in the lo… Collaboration 8.8.15+ Fix from $1,6002021-07-02 MEDIUM 5.4 CVE-2021-35208 An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 23. An attacker … Collaboration 8.8.15+ Fix from $1,6002021-07-02 MEDIUM 6.5 CVE-2020-35123 In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store exten… Collaboration 8.8.15+ Fix from $1,6002020-12-17 MEDIUM 6.1 CVE-2020-11737 A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invit… Zimbra Mitigation only Fix from $1,6002020-05-05 MEDIUM 6.5 CVE-2020-10194 cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs fro… Zm Mailbox 8.8.15+ Fix from $1,6002020-03-20 MEDIUM 6.1 CVE-2013-1938 Zimbra 2013 has XSS in aspell.php Zimbra Patch available Fix from $1,6002020-02-12 MEDIUM 6.1 CVE-2019-15313 In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability. Collaboration Server 8.8.15+ Fix from $1,6002020-01-27 MEDIUM 6.1 CVE-2019-8945 Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS. Collaboration Server after 8.8.11 Fix from $1,6002020-01-27 MEDIUM 6.1 CVE-2019-8946 Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS. Collaboration Server after 8.8.11 Fix from $1,6002020-01-27 MEDIUM 6.1 CVE-2019-8947 Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS. Collaboration Server after 8.8.11 Fix from $1,6002020-01-27 MEDIUM 6.1 CVE-2016-5721 Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTM… Zimbra Collaboration Server after 8.6.0 Fix from $1,6002016-08-29 HIGH 8.8 CVE-2015-6541 Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attacke… Zimbra Collaboration Server after 8.0.9 Fix from $1,9502016-04-08 HIGH 10.0 CVE-2013-7217 Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impact and unspecified vectors, a… Collaboration Server after 7.2.5 Fix from $1,9502013-12-26