Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Groupware MEDIUM 5.3
CVE-2025-41066

Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the existence of valid accounts on …

Mitigation only
Fix from $1,600 2025-12-02
Groupware HIGH 7.5
CVE-2017-15235EPSS 6%

The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a cra…

No fix yet
Fix from $1,950 2017-10-11
Horde Image Api HIGH 8.8
CVE-2017-9774

Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication.

Mitigation only
Fix from $1,950 2017-06-21
Horde Image MEDIUM 5.7
CVE-2017-9773

Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver.

No fix yet
Fix from $1,600 2017-06-21
Groupware HIGH 7.5
CVE-2017-7414

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP featur…

Mitigation only
Fix from $1,950 2017-04-04
Horde MEDIUM 5.0
CVE-2010-1638

The IMP plugin in Horde allows remote attackers to bypass firewall restrictions and use Horde as a proxy to scan internal networks via a crafted requ…

Mitigation only
Fix from $1,600 2010-06-22
Groupware MEDIUM 5.4
CVE-2007-1679

Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or…

Mitigation only
Fix from $1,600 2007-03-26
Imp MEDIUM 5.3
CVE-2002-2024

Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2…

Mitigation only
Fix from $1,600 2002-12-31