Show filters
132 Total Results
Displaying 21-30 of 132
Sort by:
Attacker Value
Unknown
CVE-2018-17938
Disclosure Date: October 03, 2018 (last updated November 27, 2024)
Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
0
Attacker Value
Unknown
CVE-2018-10939
Disclosure Date: May 30, 2018 (last updated November 26, 2024)
Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.
0
Attacker Value
Unknown
CVE-2015-7610
Disclosure Date: May 30, 2018 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.
0
Attacker Value
Unknown
CVE-2018-10950
Disclosure Date: May 10, 2018 (last updated November 26, 2024)
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through Verbose Error Messages containing a stack dump, tracing data, or full user-context dump.
0
Attacker Value
Unknown
CVE-2018-10949
Disclosure Date: May 10, 2018 (last updated November 26, 2024)
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.
0
Attacker Value
Unknown
CVE-2018-10951
Disclosure Date: May 10, 2018 (last updated November 26, 2024)
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API.
0
Attacker Value
Unknown
CVE-2018-6882
Disclosure Date: March 27, 2018 (last updated January 28, 2025)
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
0
Attacker Value
Unknown
CVE-2017-17703
Disclosure Date: February 04, 2018 (last updated November 26, 2024)
Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS.
0
Attacker Value
Unknown
CVE-2017-8783
Disclosure Date: February 04, 2018 (last updated November 26, 2024)
Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS.
0
Attacker Value
Unknown
CVE-2017-8802
Disclosure Date: January 16, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.8.0 Beta2 might allow remote attackers to inject arbitrary web script or HTML via vectors related to the "Show Snippet" functionality.
0