İçeriğe atla
Noroxi

Horde kayıtları

horde üreticisine ait 115 yayımlanmış kayıt.

Tüm kayıtlar

115 kayıt
  • CVE-2020-8518
    61Bu hafta

    Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.

    KritikCVSS 9,8SilahlaştırılmışEPSS %72

    horde · groupware17 Şub 2020

  • CVE-2022-30287
    53Planlayın

    Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class

    YüksekCVSS 8,0İstismar yokEPSS %71

    horde · groupware28 Tem 2022

  • CVE-2012-0209
    52Planlayın

    Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2

    YüksekCVSS 7,5SilahlaştırılmışEPSS %72

    horde · groupware25 Eyl 2012

  • CVE-2017-7413
    47Planlayın

    In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an

    YüksekCVSS 8,8İstismar yokEPSS %40

    horde · groupware4 Nis 2017

  • CVE-2014-1691
    43Planlayın

    The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object inject

    YüksekCVSS 7,5SilahlaştırılmışEPSS %43

    horde · horde application framework1 Nis 2014

  • CVE-2006-1491
    42Planlayın

    Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execu

    YüksekCVSS 7,5Kavram kanıtıEPSS %39

    horde · application framework29 Mar 2006

  • CVE-2005-3344
    42Planlayın

    The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain acce

    KritikCVSS 10,0Kavram kanıtıEPSS %8

    horde · horde16 Kas 2005

  • CVE-2019-9858
    41Planlayın

    Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %19

    horde · groupware29 May 2019

  • CVE-2008-7219
    41Planlayın

    Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3

    KritikCVSS 10,0İstismar yokEPSS %3

    horde · groupware13 Eyl 2009

  • CVE-2008-7218
    41Planlayın

    Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 be

    KritikCVSS 10,0İstismar yokEPSS %2

    horde · groupware13 Eyl 2009

  • CVE-2003-0025
    38İzleyin

    Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possi

    YüksekCVSS 7,5İstismar yokEPSS %28

    horde · imp17 Oca 2003

  • CVE-2017-9774
    36İzleyin

    Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request.

    YüksekCVSS 8,8İstismar yokEPSS %2

    horde · horde image api21 Haz 2017

  • CVE-2013-6364
    36İzleyin

    Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

    YüksekCVSS 8,8Kavram kanıtıEPSS %2

    horde · groupware5 Kas 2019

  • CVE-2008-3650
    36İzleyin

    Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related

    KritikCVSS 9,0İstismar yokEPSS %1

    horde · groupware webmail edition12 Ağu 2008

  • CVE-2019-12095
    35İzleyin

    Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmark

    YüksekCVSS 8,8İstismar yokEPSS %1

    horde · groupware24 Eki 2019

  • CVE-2017-14650
    33İzleyin

    A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "con

    YüksekCVSS 8,1İstismar yokEPSS %4

    horde · horde image api21 Eyl 2017

  • CVE-2014-3999
    33İzleyin

    The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user

    YüksekCVSS 8,1İstismar yokEPSS %2

    horde · horde ldap10 Nis 2018

  • CVE-2017-15235
    32İzleyin

    The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads

    YüksekCVSS 7,5Kavram kanıtıEPSS %6

    horde · groupware10 Eki 2017

  • CVE-2006-6175
    31İzleyin

    Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to inc

    YüksekCVSS 7,5İstismar yokEPSS %2

    horde · kronolith30 Kas 2006

  • CVE-2001-1257
    31İzleyin

    Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbit

    YüksekCVSS 7,5İstismar yokEPSS %2

    horde · imp21 Tem 2001

  • CVE-2002-0181
    31İzleyin

    Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and

    YüksekCVSS 7,5İstismar yokEPSS %2

    horde · horde22 Nis 2002

  • CVE-2017-7414
    30İzleyin

    In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has P

    YüksekCVSS 7,5İstismar yokEPSS %1

    horde · groupware4 Nis 2017

  • CVE-2020-8866
    29İzleyin

    This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22.

    OrtaCVSS 6,5Kavram kanıtıEPSS %10

    horde · groupware23 Mar 2020

  • CVE-2007-1474
    28İzleyin

    Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows l

    OrtaCVSS 6,8Kavram kanıtıEPSS %5

    horde · horde application framework16 Mar 2007

  • CVE-2015-7984
    28İzleyin

    Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail

    OrtaCVSS 6,8Kavram kanıtıEPSS %4

    horde · groupware19 Kas 2015