zarafa records
12 published records for vendor zarafa.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-20 Improper Input Validation2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-399 Resource Management Errors1
- CWE-310 Cryptographic Issues1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2015-6566No exploit | zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zazarafa · zarafa collaboration platform · CWE-59 | High8.4 | — | 0.4% | Jan 11, 2016 |
31Monitor | CVE-2021-28994No exploit | kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 kopano · groupware core · CWE-770 | High7.5 | — | 2.0% | Mar 31, 2021 |
26Monitor | CVE-2019-7219Proof of concept | Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier.zarafa · webaccess · CWE-79 | Medium6.1 | — | 5.0% | Apr 11, 2019 |
26Monitor | CVE-2015-3436No exploit | provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbizarafa · zarafa collaboration platform · CWE-59 | Medium6.6 | — | 0.4% | Jun 9, 2015 |
22Monitor | CVE-2014-5450No exploit | Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive infozarafa · zarafa collaboration platform · CWE-200 | Medium5.5 | — | 0.4% | Mar 19, 2018 |
21Monitor | CVE-2014-9465No exploit | senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x zarafa · webapp · CWE-399 | Medium5.0 | — | 3.4% | Feb 19, 2015 |
21Monitor | CVE-2014-0037No exploit | The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a denizarafa · zarafa · CWE-20 | Medium5.0 | — | 2.4% | Apr 28, 2014 |
21Monitor | CVE-2014-0079No exploit | The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditionszarafa · zarafa · CWE-20 | Medium5.0 | — | 1.8% | Apr 28, 2014 |
8Monitor | CVE-2014-0103No exploit | WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitivezarafa · webapp · CWE-310 | Low2.1 | — | 0.4% | Jul 29, 2014 |
8Monitor | CVE-2014-5448No exploit | Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by zarafa · zarafa · CWE-200 | Low2.1 | — | 0.4% | Oct 20, 2014 |
8Monitor | CVE-2014-5449No exploit | Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain senzarafa · webaccess · CWE-200 | Low2.1 | — | 0.4% | Oct 20, 2014 |
8Monitor | CVE-2014-5447No exploit | Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive informazarafa · webapp · CWE-200 | Low2.1 | — | 0.4% | Oct 20, 2014 |
- CVE-2015-656633Monitor
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/za
HighCVSS 8.4No exploitEPSS 0%zarafa · zarafa collaboration platformJan 11, 2016
- CVE-2021-2899431Monitor
kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1
HighCVSS 7.5No exploitEPSS 2%kopano · groupware coreMar 31, 2021
- CVE-2019-721926Monitor
Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier.
MediumCVSS 6.1Proof of conceptEPSS 5%zarafa · webaccessApr 11, 2019
- CVE-2015-343626Monitor
provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbi
MediumCVSS 6.6No exploitEPSS 0%zarafa · zarafa collaboration platformJun 9, 2015
- CVE-2014-545022Monitor
Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive info
MediumCVSS 5.5No exploitEPSS 0%zarafa · zarafa collaboration platformMar 19, 2018
- CVE-2014-946521Monitor
senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x
MediumCVSS 5.0No exploitEPSS 3%zarafa · webappFeb 19, 2015
- CVE-2014-003721Monitor
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a deni
MediumCVSS 5.0No exploitEPSS 2%zarafa · zarafaApr 28, 2014
- CVE-2014-007921Monitor
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions
MediumCVSS 5.0No exploitEPSS 2%zarafa · zarafaApr 28, 2014
- CVE-2014-01038Monitor
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive
LowCVSS 2.1No exploitEPSS 0%zarafa · webappJul 29, 2014
- CVE-2014-54488Monitor
Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by
LowCVSS 2.1No exploitEPSS 0%zarafa · zarafaOct 20, 2014
- CVE-2014-54498Monitor
Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sen
LowCVSS 2.1No exploitEPSS 0%zarafa · webaccessOct 20, 2014
- CVE-2014-54478Monitor
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive informa
LowCVSS 2.1No exploitEPSS 0%zarafa · webappOct 20, 2014