Записи Horde
115 опубликованных записей вендора horde.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 4 · 3,5 %
- Pre-auth RCE
- 10
- С записью об исправлении
- 59,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')43
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
115 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2020-8518Готовый эксплойт | Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.horde · groupware · CWE-94 | Критическая9,8 | — | 71,7 % | 17 февр. 2020 г. |
53В плане | CVE-2022-30287Эксплойта нет | Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver classhorde · groupware · CWE-470 | Высокая8,0 | — | 70,7 % | 28 июл. 2022 г. |
52В плане | CVE-2012-0209Готовый эксплойт | Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2horde · groupware · CWE-94 | Высокая7,5 | — | 71,9 % | 25 сент. 2012 г. |
47В плане | CVE-2017-7413Эксплойта нет | In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is anhorde · groupware · CWE-78 | Высокая8,8 | — | 40,4 % | 4 апр. 2017 г. |
43В плане | CVE-2014-1691Готовый эксплойт | The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injecthorde · horde application framework · CWE-94 | Высокая7,5 | — | 42,9 % | 1 апр. 2014 г. |
42В плане | CVE-2006-1491Proof of concept | Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execuhorde · application framework · CWE-94 | Высокая7,5 | — | 39,2 % | 29 мар. 2006 г. |
42В плане | CVE-2005-3344Proof of concept | The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain accehorde · horde | Критическая10,0 | — | 8,0 % | 16 нояб. 2005 г. |
41В плане | CVE-2019-9858Готовый эксплойт | Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17.horde · groupware · CWE-22 | Высокая8,8 | — | 18,8 % | 29 мая 2019 г. |
41В плане | CVE-2008-7219Эксплойта нет | Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3horde · groupware · CWE-264 | Критическая10,0 | — | 2,7 % | 13 сент. 2009 г. |
41В плане | CVE-2008-7218Эксплойта нет | Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 behorde · groupware | Критическая10,0 | — | 2,2 % | 13 сент. 2009 г. |
38Наблюдать | CVE-2003-0025Эксплойта нет | Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possihorde · imp | Высокая7,5 | — | 28,0 % | 17 янв. 2003 г. |
36Наблюдать | CVE-2017-9774Эксплойта нет | Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request.horde · horde image api · CWE-94 | Высокая8,8 | — | 2,4 % | 21 июн. 2017 г. |
36Наблюдать | CVE-2013-6364Proof of concept | Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address bookhorde · groupware · CWE-79 | Высокая8,8 | — | 2,1 % | 5 нояб. 2019 г. |
36Наблюдать | CVE-2008-3650Эксплойта нет | Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related horde · groupware webmail edition | Критическая9,0 | — | 1,0 % | 12 авг. 2008 г. |
35Наблюдать | CVE-2019-12095Эксплойта нет | Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkhorde · groupware · CWE-79 | Высокая8,8 | — | 1,1 % | 24 окт. 2019 г. |
33Наблюдать | CVE-2017-14650Эксплойта нет | A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "conhorde · horde image api · CWE-20 | Высокая8,1 | — | 4,0 % | 21 сент. 2017 г. |
33Наблюдать | CVE-2014-3999Эксплойта нет | The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind userhorde · horde ldap · CWE-287 | Высокая8,1 | — | 2,4 % | 10 апр. 2018 г. |
32Наблюдать | CVE-2017-15235Proof of concept | The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads horde · groupware · CWE-425 | Высокая7,5 | — | 5,5 % | 10 окт. 2017 г. |
31Наблюдать | CVE-2006-6175Эксплойта нет | Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to inchorde · kronolith | Высокая7,5 | — | 2,3 % | 30 нояб. 2006 г. |
31Наблюдать | CVE-2001-1257Эксплойта нет | Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbithorde · imp | Высокая7,5 | — | 2,0 % | 21 июл. 2001 г. |
31Наблюдать | CVE-2002-0181Эксплойта нет | Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and horde · horde | Высокая7,5 | — | 1,8 % | 22 апр. 2002 г. |
30Наблюдать | CVE-2017-7414Эксплойта нет | In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has Phorde · groupware · CWE-78 | Высокая7,5 | — | 1,2 % | 4 апр. 2017 г. |
29Наблюдать | CVE-2020-8866Proof of concept | This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22.horde · groupware · CWE-434 | Средняя6,5 | — | 9,6 % | 23 мар. 2020 г. |
28Наблюдать | CVE-2007-1474Proof of concept | Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows lhorde · horde application framework | Средняя6,8 | — | 4,9 % | 16 мар. 2007 г. |
28Наблюдать | CVE-2015-7984Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmailhorde · groupware · CWE-352 | Средняя6,8 | — | 4,1 % | 19 нояб. 2015 г. |
- CVE-2020-851861На этой неделе
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
КритическаяCVSS 9,8Готовый эксплойтEPSS 72 %horde · groupware17 февр. 2020 г.
- CVE-2022-3028753В плане
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class
ВысокаяCVSS 8,0Эксплойта нетEPSS 71 %horde · groupware28 июл. 2022 г.
- CVE-2012-020952В плане
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2
ВысокаяCVSS 7,5Готовый эксплойтEPSS 72 %horde · groupware25 сент. 2012 г.
- CVE-2017-741347В плане
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an
ВысокаяCVSS 8,8Эксплойта нетEPSS 40 %horde · groupware4 апр. 2017 г.
- CVE-2014-169143В плане
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object inject
ВысокаяCVSS 7,5Готовый эксплойтEPSS 43 %horde · horde application framework1 апр. 2014 г.
- CVE-2006-149142В плане
Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execu
ВысокаяCVSS 7,5Proof of conceptEPSS 39 %horde · application framework29 мар. 2006 г.
- CVE-2005-334442В плане
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain acce
КритическаяCVSS 10,0Proof of conceptEPSS 8 %horde · horde16 нояб. 2005 г.
- CVE-2019-985841В плане
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 19 %horde · groupware29 мая 2019 г.
- CVE-2008-721941В плане
Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %horde · groupware13 сент. 2009 г.
- CVE-2008-721841В плане
Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 be
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %horde · groupware13 сент. 2009 г.
- CVE-2003-002538Наблюдать
Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possi
ВысокаяCVSS 7,5Эксплойта нетEPSS 28 %horde · imp17 янв. 2003 г.
- CVE-2017-977436Наблюдать
Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %horde · horde image api21 июн. 2017 г.
- CVE-2013-636436Наблюдать
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %horde · groupware5 нояб. 2019 г.
- CVE-2008-365036Наблюдать
Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %horde · groupware webmail edition12 авг. 2008 г.
- CVE-2019-1209535Наблюдать
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmark
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %horde · groupware24 окт. 2019 г.
- CVE-2017-1465033Наблюдать
A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "con
ВысокаяCVSS 8,1Эксплойта нетEPSS 4 %horde · horde image api21 сент. 2017 г.
- CVE-2014-399933Наблюдать
The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %horde · horde ldap10 апр. 2018 г.
- CVE-2017-1523532Наблюдать
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %horde · groupware10 окт. 2017 г.
- CVE-2006-617531Наблюдать
Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to inc
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %horde · kronolith30 нояб. 2006 г.
- CVE-2001-125731Наблюдать
Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbit
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %horde · imp21 июл. 2001 г.
- CVE-2002-018131Наблюдать
Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %horde · horde22 апр. 2002 г.
- CVE-2017-741430Наблюдать
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has P
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %horde · groupware4 апр. 2017 г.
- CVE-2020-886629Наблюдать
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22.
СредняяCVSS 6,5Proof of conceptEPSS 10 %horde · groupware23 мар. 2020 г.
- CVE-2007-147428Наблюдать
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows l
СредняяCVSS 6,8Proof of conceptEPSS 5 %horde · horde application framework16 мар. 2007 г.
- CVE-2015-798428Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail
СредняяCVSS 6,8Proof of conceptEPSS 4 %horde · groupware19 нояб. 2015 г.