Show filters
29 Total Results
Displaying 1-10 of 29
Sort by:
Attacker Value
Moderate
CVE-2024-45519
Disclosure Date: October 02, 2024 (last updated October 16, 2024)
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
1
Attacker Value
Unknown
CVE-2024-45518
Disclosure Date: October 22, 2024 (last updated October 31, 2024)
An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Side Request Forgery (SSRF) due to improper input sanitization and misconfigured domain whitelisting. This issue permits unauthorized HTTP requests to be sent to internal services, which can lead to Remote Code Execution (RCE) by chaining Command Injection within the internal service. When combined with existing XSS vulnerabilities, this SSRF issue can further facilitate Remote Code Execution (RCE).
0
Attacker Value
Unknown
CVE-2008-1814
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the Oracle Secure Enterprise Search or Ultrasearch component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3 and 10.1.2.2; and Oracle Collaboration Suite 10.1.2; has unknown impact and remote attack vectors, aka DB04.
0
Attacker Value
Unknown
CVE-2008-0346
Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka AS01.
0
Attacker Value
Unknown
CVE-2008-0345
Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.
0
Attacker Value
Unknown
CVE-2008-0343
Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and remote attack vectors, aka DB06.
0
Attacker Value
Unknown
CVE-2008-0340
Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to the (1) Advanced Queuing component (DB02) and (2) Oracle Spatial component (DB04).
0
Attacker Value
Unknown
CVE-2008-0349
Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02.
0
Attacker Value
Unknown
CVE-2008-0344
Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka DB07.
0
Attacker Value
Unknown
CVE-2008-0348
Disclosure Date: January 17, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vectors, aka (1) PSE01, (2) PSE03, and (3) PSE04.
0