Search CVE reports


Toggle filters

41 – 50 of 71 results


CVE-2015-2181

Medium priority
Ignored

Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2015-2180

Medium priority
Ignored

The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2016-4552

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2016-9920

Medium priority
Vulnerable

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-4069

Medium priority
Vulnerable

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2015-8794

Medium priority
Ignored

Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter,...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2015-8793

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter in a mail task to the...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2015-8770

Medium priority
Ignored

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2015-8105

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2015-1433

Medium priority
Ignored

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages