Horde kayıtları
horde üreticisine ait 115 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 4 · %3,5
- Pre-auth RCE
- 10
- Düzeltme kaydı olan
- %59,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')43
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
115 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2020-8518Silahlaştırılmış | Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.horde · groupware · CWE-94 | Kritik9,8 | — | %71,7 | 17 Şub 2020 |
53Planlayın | CVE-2022-30287İstismar yok | Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver classhorde · groupware · CWE-470 | Yüksek8,0 | — | %70,7 | 28 Tem 2022 |
52Planlayın | CVE-2012-0209Silahlaştırılmış | Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2horde · groupware · CWE-94 | Yüksek7,5 | — | %71,9 | 25 Eyl 2012 |
47Planlayın | CVE-2017-7413İstismar yok | In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is anhorde · groupware · CWE-78 | Yüksek8,8 | — | %40,4 | 4 Nis 2017 |
43Planlayın | CVE-2014-1691Silahlaştırılmış | The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injecthorde · horde application framework · CWE-94 | Yüksek7,5 | — | %42,9 | 1 Nis 2014 |
42Planlayın | CVE-2006-1491Kavram kanıtı | Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execuhorde · application framework · CWE-94 | Yüksek7,5 | — | %39,2 | 29 Mar 2006 |
42Planlayın | CVE-2005-3344Kavram kanıtı | The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain accehorde · horde | Kritik10,0 | — | %8,0 | 16 Kas 2005 |
41Planlayın | CVE-2019-9858Silahlaştırılmış | Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17.horde · groupware · CWE-22 | Yüksek8,8 | — | %18,8 | 29 May 2019 |
41Planlayın | CVE-2008-7219İstismar yok | Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3horde · groupware · CWE-264 | Kritik10,0 | — | %2,7 | 13 Eyl 2009 |
41Planlayın | CVE-2008-7218İstismar yok | Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 behorde · groupware | Kritik10,0 | — | %2,2 | 13 Eyl 2009 |
38İzleyin | CVE-2003-0025İstismar yok | Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possihorde · imp | Yüksek7,5 | — | %28,0 | 17 Oca 2003 |
36İzleyin | CVE-2017-9774İstismar yok | Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request.horde · horde image api · CWE-94 | Yüksek8,8 | — | %2,4 | 21 Haz 2017 |
36İzleyin | CVE-2013-6364Kavram kanıtı | Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address bookhorde · groupware · CWE-79 | Yüksek8,8 | — | %2,1 | 5 Kas 2019 |
36İzleyin | CVE-2008-3650İstismar yok | Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related horde · groupware webmail edition | Kritik9,0 | — | %1,0 | 12 Ağu 2008 |
35İzleyin | CVE-2019-12095İstismar yok | Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkhorde · groupware · CWE-79 | Yüksek8,8 | — | %1,1 | 24 Eki 2019 |
33İzleyin | CVE-2017-14650İstismar yok | A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "conhorde · horde image api · CWE-20 | Yüksek8,1 | — | %4,0 | 21 Eyl 2017 |
33İzleyin | CVE-2014-3999İstismar yok | The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind userhorde · horde ldap · CWE-287 | Yüksek8,1 | — | %2,4 | 10 Nis 2018 |
32İzleyin | CVE-2017-15235Kavram kanıtı | The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads horde · groupware · CWE-425 | Yüksek7,5 | — | %5,5 | 10 Eki 2017 |
31İzleyin | CVE-2006-6175İstismar yok | Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to inchorde · kronolith | Yüksek7,5 | — | %2,3 | 30 Kas 2006 |
31İzleyin | CVE-2001-1257İstismar yok | Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbithorde · imp | Yüksek7,5 | — | %2,0 | 21 Tem 2001 |
31İzleyin | CVE-2002-0181İstismar yok | Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and horde · horde | Yüksek7,5 | — | %1,8 | 22 Nis 2002 |
30İzleyin | CVE-2017-7414İstismar yok | In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has Phorde · groupware · CWE-78 | Yüksek7,5 | — | %1,2 | 4 Nis 2017 |
29İzleyin | CVE-2020-8866Kavram kanıtı | This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22.horde · groupware · CWE-434 | Orta6,5 | — | %9,6 | 23 Mar 2020 |
28İzleyin | CVE-2007-1474Kavram kanıtı | Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows lhorde · horde application framework | Orta6,8 | — | %4,9 | 16 Mar 2007 |
28İzleyin | CVE-2015-7984Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmailhorde · groupware · CWE-352 | Orta6,8 | — | %4,1 | 19 Kas 2015 |
- CVE-2020-851861Bu hafta
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
KritikCVSS 9,8SilahlaştırılmışEPSS %72horde · groupware17 Şub 2020
- CVE-2022-3028753Planlayın
Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class
YüksekCVSS 8,0İstismar yokEPSS %71horde · groupware28 Tem 2022
- CVE-2012-020952Planlayın
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2
YüksekCVSS 7,5SilahlaştırılmışEPSS %72horde · groupware25 Eyl 2012
- CVE-2017-741347Planlayın
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an
YüksekCVSS 8,8İstismar yokEPSS %40horde · groupware4 Nis 2017
- CVE-2014-169143Planlayın
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object inject
YüksekCVSS 7,5SilahlaştırılmışEPSS %43horde · horde application framework1 Nis 2014
- CVE-2006-149142Planlayın
Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execu
YüksekCVSS 7,5Kavram kanıtıEPSS %39horde · application framework29 Mar 2006
- CVE-2005-334442Planlayın
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain acce
KritikCVSS 10,0Kavram kanıtıEPSS %8horde · horde16 Kas 2005
- CVE-2019-985841Planlayın
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17.
YüksekCVSS 8,8SilahlaştırılmışEPSS %19horde · groupware29 May 2019
- CVE-2008-721941Planlayın
Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3
KritikCVSS 10,0İstismar yokEPSS %3horde · groupware13 Eyl 2009
- CVE-2008-721841Planlayın
Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 be
KritikCVSS 10,0İstismar yokEPSS %2horde · groupware13 Eyl 2009
- CVE-2003-002538İzleyin
Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possi
YüksekCVSS 7,5İstismar yokEPSS %28horde · imp17 Oca 2003
- CVE-2017-977436İzleyin
Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request.
YüksekCVSS 8,8İstismar yokEPSS %2horde · horde image api21 Haz 2017
- CVE-2013-636436İzleyin
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
YüksekCVSS 8,8Kavram kanıtıEPSS %2horde · groupware5 Kas 2019
- CVE-2008-365036İzleyin
Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related
KritikCVSS 9,0İstismar yokEPSS %1horde · groupware webmail edition12 Ağu 2008
- CVE-2019-1209535İzleyin
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmark
YüksekCVSS 8,8İstismar yokEPSS %1horde · groupware24 Eki 2019
- CVE-2017-1465033İzleyin
A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "con
YüksekCVSS 8,1İstismar yokEPSS %4horde · horde image api21 Eyl 2017
- CVE-2014-399933İzleyin
The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user
YüksekCVSS 8,1İstismar yokEPSS %2horde · horde ldap10 Nis 2018
- CVE-2017-1523532İzleyin
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads
YüksekCVSS 7,5Kavram kanıtıEPSS %6horde · groupware10 Eki 2017
- CVE-2006-617531İzleyin
Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to inc
YüksekCVSS 7,5İstismar yokEPSS %2horde · kronolith30 Kas 2006
- CVE-2001-125731İzleyin
Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbit
YüksekCVSS 7,5İstismar yokEPSS %2horde · imp21 Tem 2001
- CVE-2002-018131İzleyin
Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and
YüksekCVSS 7,5İstismar yokEPSS %2horde · horde22 Nis 2002
- CVE-2017-741430İzleyin
In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has P
YüksekCVSS 7,5İstismar yokEPSS %1horde · groupware4 Nis 2017
- CVE-2020-886629İzleyin
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22.
OrtaCVSS 6,5Kavram kanıtıEPSS %10horde · groupware23 Mar 2020
- CVE-2007-147428İzleyin
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows l
OrtaCVSS 6,8Kavram kanıtıEPSS %5horde · horde application framework16 Mar 2007
- CVE-2015-798428İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail
OrtaCVSS 6,8Kavram kanıtıEPSS %4horde · groupware19 Kas 2015