Skip to content
Noroxi

zarafa records

12 published records for vendor zarafa.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

12 records
  • CVE-2015-6566
    33Monitor

    zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/za

    HighCVSS 8.4No exploitEPSS 0%

    zarafa · zarafa collaboration platformJan 11, 2016

  • kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1

    HighCVSS 7.5No exploitEPSS 2%

    kopano · groupware coreMar 31, 2021

  • CVE-2019-7219
    26Monitor

    Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier.

    MediumCVSS 6.1Proof of conceptEPSS 5%

    zarafa · webaccessApr 11, 2019

  • CVE-2015-3436
    26Monitor

    provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbi

    MediumCVSS 6.6No exploitEPSS 0%

    zarafa · zarafa collaboration platformJun 9, 2015

  • CVE-2014-5450
    22Monitor

    Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive info

    MediumCVSS 5.5No exploitEPSS 0%

    zarafa · zarafa collaboration platformMar 19, 2018

  • CVE-2014-9465
    21Monitor

    senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x

    MediumCVSS 5.0No exploitEPSS 3%

    zarafa · webappFeb 19, 2015

  • CVE-2014-0037
    21Monitor

    The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a deni

    MediumCVSS 5.0No exploitEPSS 2%

    zarafa · zarafaApr 28, 2014

  • CVE-2014-0079
    21Monitor

    The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions

    MediumCVSS 5.0No exploitEPSS 2%

    zarafa · zarafaApr 28, 2014

  • WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive

    LowCVSS 2.1No exploitEPSS 0%

    zarafa · webappJul 29, 2014

  • Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by

    LowCVSS 2.1No exploitEPSS 0%

    zarafa · zarafaOct 20, 2014

  • Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sen

    LowCVSS 2.1No exploitEPSS 0%

    zarafa · webaccessOct 20, 2014

  • Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive informa

    LowCVSS 2.1No exploitEPSS 0%

    zarafa · webappOct 20, 2014