Show filters
202 Total Results
Displaying 31-40 of 202
Sort by:
Attacker Value
Unknown
CVE-2020-12713
Disclosure Date: June 11, 2020 (last updated February 21, 2025)
An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web interface have multiple options to escalate their privileges to the Unix root account.
0
Attacker Value
Unknown
CVE-2020-12714
Disclosure Date: June 11, 2020 (last updated February 21, 2025)
An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual Appliances versions 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger Virtual Appliances 1.1.1 through 3.1.1-0. A Diffie-Hellman parameter of insufficient size could allow man-in-the-middle compromise of communications between CipherMail products and external SMTP clients.
0
Attacker Value
Unknown
CVE-2020-13965
Disclosure Date: June 09, 2020 (last updated February 21, 2025)
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
0
Attacker Value
Unknown
CVE-2020-13964
Disclosure Date: June 09, 2020 (last updated February 21, 2025)
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.
0
Attacker Value
Unknown
CVE-2020-12641
Disclosure Date: May 04, 2020 (last updated February 21, 2025)
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
0
Attacker Value
Unknown
CVE-2020-12640
Disclosure Date: May 04, 2020 (last updated February 21, 2025)
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
0
Attacker Value
Unknown
CVE-2020-12625
Disclosure Date: May 04, 2020 (last updated February 21, 2025)
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
0
Attacker Value
Unknown
CVE-2020-12626
Disclosure Date: May 04, 2020 (last updated February 21, 2025)
An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.
0
Attacker Value
Unknown
CVE-2019-13389
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.
0
Attacker Value
Unknown
CVE-2012-5570
Disclosure Date: February 08, 2020 (last updated February 21, 2025)
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.
0