İçeriğe atla
Noroxi

zarafa kayıtları

zarafa üreticisine ait 12 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

12 kayıt
  • CVE-2015-6566
    33İzleyin

    zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/za

    YüksekCVSS 8,4İstismar yokEPSS %0

    zarafa · zarafa collaboration platform11 Oca 2016

  • CVE-2021-28994
    31İzleyin

    kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1

    YüksekCVSS 7,5İstismar yokEPSS %2

    kopano · groupware core31 Mar 2021

  • CVE-2019-7219
    26İzleyin

    Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier.

    OrtaCVSS 6,1Kavram kanıtıEPSS %5

    zarafa · webaccess11 Nis 2019

  • CVE-2015-3436
    26İzleyin

    provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbi

    OrtaCVSS 6,6İstismar yokEPSS %0

    zarafa · zarafa collaboration platform9 Haz 2015

  • CVE-2014-5450
    22İzleyin

    Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive info

    OrtaCVSS 5,5İstismar yokEPSS %0

    zarafa · zarafa collaboration platform19 Mar 2018

  • CVE-2014-9465
    21İzleyin

    senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x

    OrtaCVSS 5,0İstismar yokEPSS %3

    zarafa · webapp19 Şub 2015

  • CVE-2014-0037
    21İzleyin

    The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a deni

    OrtaCVSS 5,0İstismar yokEPSS %2

    zarafa · zarafa28 Nis 2014

  • CVE-2014-0079
    21İzleyin

    The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions

    OrtaCVSS 5,0İstismar yokEPSS %2

    zarafa · zarafa28 Nis 2014

  • CVE-2014-0103
    8İzleyin

    WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive

    DüşükCVSS 2,1İstismar yokEPSS %0

    zarafa · webapp29 Tem 2014

  • CVE-2014-5448
    8İzleyin

    Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by

    DüşükCVSS 2,1İstismar yokEPSS %0

    zarafa · zarafa20 Eki 2014

  • CVE-2014-5449
    8İzleyin

    Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sen

    DüşükCVSS 2,1İstismar yokEPSS %0

    zarafa · webaccess20 Eki 2014

  • CVE-2014-5447
    8İzleyin

    Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive informa

    DüşükCVSS 2,1İstismar yokEPSS %0

    zarafa · webapp20 Eki 2014