İçeriğe atla
Noroxi

Alinto kayıtları

alinto üreticisine ait 16 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%100
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

16 kayıt
  • CVE-2015-5395
    35İzleyin

    Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.

    YüksekCVSS 8,8İstismar yokEPSS %1

    debian · debian linux20 Eyl 2017

  • CVE-2016-6188
    27İzleyin

    Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload

    OrtaCVSS 6,5İstismar yokEPSS %2

    alinto · sogo3 Şub 2017

  • CVE-2014-9905
    24İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web

    OrtaCVSS 6,1İstismar yokEPSS %1

    alinto · sogo17 Şub 2017

  • CVE-2016-6191
    24İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attack

    OrtaCVSS 6,1İstismar yokEPSS %1

    alinto · sogo17 Şub 2017

  • CVE-2023-48104
    24İzleyin

    Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    alinto · sogo15 Oca 2024

  • CVE-2022-4556
    24İzleyin

    Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scripting

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    alinto · sogo16 Ara 2022

  • CVE-2022-4558
    24İzleyin

    Alinto SOGo Folder/Mail NSString+Utilities.m cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    alinto · sogo16 Ara 2022

  • CVE-2024-24510
    24İzleyin

    Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function t

    OrtaCVSS 6,1İstismar yokEPSS %0

    alinto · sogo9 Eyl 2024

  • CVE-2020-22402
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user rea

    OrtaCVSS 6,1İstismar yokEPSS %0

    alinto · sogo web mail14 Haz 2023

  • CVE-2024-34462
    24İzleyin

    Alinto SOGo through 5.10.0 allows XSS during attachment preview.

    OrtaCVSS 6,1İstismar yokEPSS %0

    alinto · sogo4 May 2024

  • CVE-2025-63499
    24İzleyin

    Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.

    OrtaCVSS 6,1Kavram kanıtıEPSS %0

    alinto · sogo4 Ara 2025

  • CVE-2025-63498
    24İzleyin

    alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

    OrtaCVSS 6,1Kavram kanıtıEPSS %0

    alinto · sogo24 Kas 2025

  • CVE-2025-71276
    24İzleyin

    SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.

    OrtaCVSS 6,1İstismar yokEPSS %0

    alinto · sogo21 Mar 2026

  • CVE-2016-6189
    17İzleyin

    Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading

    OrtaCVSS 4,3İstismar yokEPSS %1

    alinto · sogo17 Şub 2017

  • CVE-2026-33550
    10İzleyin

    SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recomm

    DüşükCVSS 2,6İstismar yokEPSS %0

    alinto · sogo21 Mar 2026

  • CVE-2026-3054
    8İzleyin

    Alinto SOGo cross site scripting

    DüşükCVSS 2,1İstismar yokEPSS %0

    alinto · sogo23 Şub 2026