Перейти к содержимому
Noroxi

Записи Horde

115 опубликованных записей вендора horde.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
4 · 3,5 %
Pre-auth RCE
10
С записью об исправлении
59,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

115 записей
  • CVE-2020-8518
    61На этой неделе

    Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 72 %

    horde · groupware17 февр. 2020 г.

  • CVE-2022-30287
    53В плане

    Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class

    ВысокаяCVSS 8,0Эксплойта нетEPSS 71 %

    horde · groupware28 июл. 2022 г.

  • CVE-2012-0209
    52В плане

    Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 72 %

    horde · groupware25 сент. 2012 г.

  • CVE-2017-7413
    47В плане

    In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an

    ВысокаяCVSS 8,8Эксплойта нетEPSS 40 %

    horde · groupware4 апр. 2017 г.

  • CVE-2014-1691
    43В плане

    The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object inject

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 43 %

    horde · horde application framework1 апр. 2014 г.

  • CVE-2006-1491
    42В плане

    Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execu

    ВысокаяCVSS 7,5Proof of conceptEPSS 39 %

    horde · application framework29 мар. 2006 г.

  • CVE-2005-3344
    42В плане

    The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain acce

    КритическаяCVSS 10,0Proof of conceptEPSS 8 %

    horde · horde16 нояб. 2005 г.

  • CVE-2019-9858
    41В плане

    Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17.

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 19 %

    horde · groupware29 мая 2019 г.

  • CVE-2008-7219
    41В плане

    Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    horde · groupware13 сент. 2009 г.

  • CVE-2008-7218
    41В плане

    Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 be

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    horde · groupware13 сент. 2009 г.

  • CVE-2003-0025
    38Наблюдать

    Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 28 %

    horde · imp17 янв. 2003 г.

  • CVE-2017-9774
    36Наблюдать

    Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    horde · horde image api21 июн. 2017 г.

  • CVE-2013-6364
    36Наблюдать

    Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

    ВысокаяCVSS 8,8Proof of conceptEPSS 2 %

    horde · groupware5 нояб. 2019 г.

  • CVE-2008-3650
    36Наблюдать

    Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related

    КритическаяCVSS 9,0Эксплойта нетEPSS 1 %

    horde · groupware webmail edition12 авг. 2008 г.

  • CVE-2019-12095
    35Наблюдать

    Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmark

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    horde · groupware24 окт. 2019 г.

  • CVE-2017-14650
    33Наблюдать

    A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "con

    ВысокаяCVSS 8,1Эксплойта нетEPSS 4 %

    horde · horde image api21 сент. 2017 г.

  • CVE-2014-3999
    33Наблюдать

    The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user

    ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %

    horde · horde ldap10 апр. 2018 г.

  • CVE-2017-15235
    32Наблюдать

    The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads

    ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

    horde · groupware10 окт. 2017 г.

  • CVE-2006-6175
    31Наблюдать

    Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to inc

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    horde · kronolith30 нояб. 2006 г.

  • CVE-2001-1257
    31Наблюдать

    Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbit

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    horde · imp21 июл. 2001 г.

  • CVE-2002-0181
    31Наблюдать

    Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    horde · horde22 апр. 2002 г.

  • CVE-2017-7414
    30Наблюдать

    In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has P

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    horde · groupware4 апр. 2017 г.

  • CVE-2020-8866
    29Наблюдать

    This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22.

    СредняяCVSS 6,5Proof of conceptEPSS 10 %

    horde · groupware23 мар. 2020 г.

  • CVE-2007-1474
    28Наблюдать

    Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows l

    СредняяCVSS 6,8Proof of conceptEPSS 5 %

    horde · horde application framework16 мар. 2007 г.

  • CVE-2015-7984
    28Наблюдать

    Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail

    СредняяCVSS 6,8Proof of conceptEPSS 4 %

    horde · groupware19 нояб. 2015 г.