Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Zimbra_collaboration_suite
(Synacor)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 49 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-05-29 | CVE-2019-9670 | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml. | Zimbra_collaboration_suite | 9.8 | ||
2022-10-17 | CVE-2022-3569 | Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'. | Zimbra_collaboration_suite | 7.8 | ||
2021-12-15 | CVE-2020-18984 | A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a host header injection. | Zimbra_collaboration_suite | 6.1 | ||
2021-12-15 | CVE-2020-18985 | An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing. | Zimbra_collaboration_suite | 6.1 | ||
2018-10-03 | CVE-2018-17938 | Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value. | Zimbra_collaboration_suite | 5.3 | ||
2018-05-10 | CVE-2018-10949 | mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors. | Zimbra_collaboration_suite | 5.3 | ||
2020-07-02 | CVE-2020-13653 | An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user's profile. The injected code can be reflected and executed when changing an e-mail signature. | Zimbra_collaboration_suite | N/A | ||
2018-05-10 | CVE-2018-10951 | mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API. | Zimbra_collaboration_suite, Zimbra_collaboration_suite | 6.5 | ||
2018-05-30 | CVE-2018-10939 | Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group. | Zimbra_collaboration_suite, Zimbra_collaboration_suite | 6.1 |