Show filters
50 Total Results
Displaying 21-30 of 50
Sort by:
Attacker Value
Unknown
CVE-2018-10950
Disclosure Date: May 10, 2018 (last updated November 26, 2024)
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through Verbose Error Messages containing a stack dump, tracing data, or full user-context dump.
0
Attacker Value
Unknown
CVE-2018-10951
Disclosure Date: May 10, 2018 (last updated November 26, 2024)
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API.
0
Attacker Value
Unknown
CVE-2018-10949
Disclosure Date: May 10, 2018 (last updated November 26, 2024)
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.
0
Attacker Value
Unknown
CVE-2018-6882
Disclosure Date: March 27, 2018 (last updated January 28, 2025)
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
0
Attacker Value
Unknown
CVE-2017-17703
Disclosure Date: February 04, 2018 (last updated November 26, 2024)
Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS.
0
Attacker Value
Unknown
CVE-2017-8783
Disclosure Date: February 04, 2018 (last updated November 26, 2024)
Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS.
0
Attacker Value
Unknown
CVE-2017-8802
Disclosure Date: January 16, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.8.0 Beta2 might allow remote attackers to inject arbitrary web script or HTML via vectors related to the "Show Snippet" functionality.
0
Attacker Value
Unknown
CVE-2017-6821
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2017-7288
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-6813
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations.
0