Show filters
132 Total Results
Displaying 31-40 of 132
Sort by:
Attacker Value
Unknown

CVE-2017-9805

Disclosure Date: September 15, 2017 (last updated July 26, 2024)
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Attacker Value
Unknown

CVE-2017-6821

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2017-7288

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-6813

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations.
0
Attacker Value
Unknown

CVE-2016-3403

Disclosure Date: May 17, 2017 (last updated November 26, 2024)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add, (2) modify, or (3) remove accounts by leveraging failure to use of a CSRF token and perform referer header checks, aka bugs 100885 and 100899.
0
Attacker Value
Unknown

CVE-2016-9924

Disclosure Date: March 29, 2017 (last updated November 26, 2024)
Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.
0
Attacker Value
Unknown

CVE-2016-3401

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote authenticated users to affect integrity via unknown vectors, aka bug 99810.
0
Attacker Value
Unknown

CVE-2016-3405

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Multiple unspecified vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to affect integrity via unknown vectors, aka bugs 103961 and 104828.
0
Attacker Value
Unknown

CVE-2016-3999

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104552 and 104703.
0
Attacker Value
Unknown

CVE-2016-3402

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect confidentiality via unknown vectors, aka bug 99167.
0