Перейти к содержимому
Noroxi

Записи Alinto

16 опубликованных записей вендора alinto.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
100 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 17
  2. 22
  3. 23
  4. 24
  5. 25
  6. 26

Столбик: всего · тёмная часть: CISA KEV.

Все записи

16 записей
  • CVE-2015-5395
    35Наблюдать

    Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    debian · debian linux20 сент. 2017 г.

  • CVE-2016-6188
    27Наблюдать

    Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    alinto · sogo3 февр. 2017 г.

  • CVE-2014-9905
    24Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    alinto · sogo17 февр. 2017 г.

  • CVE-2016-6191
    24Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attack

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    alinto · sogo17 февр. 2017 г.

  • CVE-2023-48104
    24Наблюдать

    Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    alinto · sogo15 янв. 2024 г.

  • CVE-2022-4556
    24Наблюдать

    Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scripting

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    alinto · sogo16 дек. 2022 г.

  • CVE-2022-4558
    24Наблюдать

    Alinto SOGo Folder/Mail NSString+Utilities.m cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    alinto · sogo16 дек. 2022 г.

  • CVE-2024-24510
    24Наблюдать

    Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function t

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    alinto · sogo9 сент. 2024 г.

  • CVE-2020-22402
    24Наблюдать

    Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user rea

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    alinto · sogo web mail14 июн. 2023 г.

  • CVE-2024-34462
    24Наблюдать

    Alinto SOGo through 5.10.0 allows XSS during attachment preview.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    alinto · sogo4 мая 2024 г.

  • CVE-2025-63499
    24Наблюдать

    Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.

    СредняяCVSS 6,1Proof of conceptEPSS 0 %

    alinto · sogo4 дек. 2025 г.

  • CVE-2025-63498
    24Наблюдать

    alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

    СредняяCVSS 6,1Proof of conceptEPSS 0 %

    alinto · sogo24 нояб. 2025 г.

  • CVE-2025-71276
    24Наблюдать

    SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    alinto · sogo21 мар. 2026 г.

  • CVE-2016-6189
    17Наблюдать

    Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    alinto · sogo17 февр. 2017 г.

  • CVE-2026-33550
    10Наблюдать

    SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recomm

    НизкаяCVSS 2,6Эксплойта нетEPSS 0 %

    alinto · sogo21 мар. 2026 г.

  • CVE-2026-3054
    8Наблюдать

    Alinto SOGo cross site scripting

    НизкаяCVSS 2,1Эксплойта нетEPSS 0 %

    alinto · sogo23 февр. 2026 г.