Show filters
202 Total Results
Displaying 61-70 of 202
Sort by:
Attacker Value
Unknown
CVE-2015-2181
Disclosure Date: January 30, 2017 (last updated November 25, 2024)
Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.
0
Attacker Value
Unknown
CVE-2016-4552
Disclosure Date: December 20, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.
0
Attacker Value
Unknown
CVE-2016-9920
Disclosure Date: December 08, 2016 (last updated November 25, 2024)
steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.
0
Attacker Value
Unknown
CVE-2016-4069
Disclosure Date: August 25, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-8770
Disclosure Date: January 29, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.
0
Attacker Value
Unknown
CVE-2015-8793
Disclosure Date: January 29, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter in a mail task to the default URL, a different vulnerability than CVE-2011-2937.
0
Attacker Value
Unknown
CVE-2015-8794
Disclosure Date: January 29, 2016 (last updated November 25, 2024)
Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to contact photo handling.
0
Attacker Value
Unknown
CVE-2015-8105
Disclosure Date: November 10, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.
0
Attacker Value
Unknown
CVE-2015-2349
Disclosure Date: March 19, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTMLForm parameter.
0
Attacker Value
Unknown
CVE-2015-1433
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.
0