CVE-2017-17688
- EPSS 2.85%
- Veröffentlicht 16.05.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:18:27
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification ...
CVE-2018-9846
- EPSS 1.01%
- Veröffentlicht 07.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:47
In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to pe...
CVE-2018-1000071
- EPSS 0.29%
- Veröffentlicht 13.03.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:34
roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.
CVE-2017-16651
- EPSS 38.27%
- Veröffentlicht 09.11.2017 14:29:00
- Zuletzt bearbeitet 22.10.2025 00:16:05
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to...
CVE-2015-5382
- EPSS 1.04%
- Veröffentlicht 23.05.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
CVE-2015-5383
- EPSS 1.8%
- Veröffentlicht 23.05.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.
CVE-2015-5381
- EPSS 1.18%
- Veröffentlicht 23.05.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
CVE-2017-8114
- EPSS 0.63%
- Veröffentlicht 29.04.2017 19:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers...
CVE-2016-4068
- EPSS 0.48%
- Veröffentlicht 13.04.2017 14:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.
CVE-2015-8864
- EPSS 0.48%
- Veröffentlicht 13.04.2017 14:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.