zarafa kayıtları
zarafa üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-20 Improper Input Validation2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-399 Resource Management Errors1
- CWE-310 Cryptographic Issues1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
33İzleyin | CVE-2015-6566İstismar yok | zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zazarafa · zarafa collaboration platform · CWE-59 | Yüksek8,4 | — | %0,4 | 11 Oca 2016 |
31İzleyin | CVE-2021-28994İstismar yok | kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 kopano · groupware core · CWE-770 | Yüksek7,5 | — | %2,0 | 31 Mar 2021 |
26İzleyin | CVE-2019-7219Kavram kanıtı | Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier.zarafa · webaccess · CWE-79 | Orta6,1 | — | %5,0 | 11 Nis 2019 |
26İzleyin | CVE-2015-3436İstismar yok | provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbizarafa · zarafa collaboration platform · CWE-59 | Orta6,6 | — | %0,4 | 9 Haz 2015 |
22İzleyin | CVE-2014-5450İstismar yok | Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive infozarafa · zarafa collaboration platform · CWE-200 | Orta5,5 | — | %0,4 | 19 Mar 2018 |
21İzleyin | CVE-2014-9465İstismar yok | senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x zarafa · webapp · CWE-399 | Orta5,0 | — | %3,4 | 19 Şub 2015 |
21İzleyin | CVE-2014-0037İstismar yok | The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a denizarafa · zarafa · CWE-20 | Orta5,0 | — | %2,4 | 28 Nis 2014 |
21İzleyin | CVE-2014-0079İstismar yok | The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditionszarafa · zarafa · CWE-20 | Orta5,0 | — | %1,8 | 28 Nis 2014 |
8İzleyin | CVE-2014-0103İstismar yok | WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitivezarafa · webapp · CWE-310 | Düşük2,1 | — | %0,4 | 29 Tem 2014 |
8İzleyin | CVE-2014-5448İstismar yok | Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by zarafa · zarafa · CWE-200 | Düşük2,1 | — | %0,4 | 20 Eki 2014 |
8İzleyin | CVE-2014-5449İstismar yok | Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain senzarafa · webaccess · CWE-200 | Düşük2,1 | — | %0,4 | 20 Eki 2014 |
8İzleyin | CVE-2014-5447İstismar yok | Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive informazarafa · webapp · CWE-200 | Düşük2,1 | — | %0,4 | 20 Eki 2014 |
- CVE-2015-656633İzleyin
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/za
YüksekCVSS 8,4İstismar yokEPSS %0zarafa · zarafa collaboration platform11 Oca 2016
- CVE-2021-2899431İzleyin
kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1
YüksekCVSS 7,5İstismar yokEPSS %2kopano · groupware core31 Mar 2021
- CVE-2019-721926İzleyin
Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier.
OrtaCVSS 6,1Kavram kanıtıEPSS %5zarafa · webaccess11 Nis 2019
- CVE-2015-343626İzleyin
provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbi
OrtaCVSS 6,6İstismar yokEPSS %0zarafa · zarafa collaboration platform9 Haz 2015
- CVE-2014-545022İzleyin
Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive info
OrtaCVSS 5,5İstismar yokEPSS %0zarafa · zarafa collaboration platform19 Mar 2018
- CVE-2014-946521İzleyin
senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x
OrtaCVSS 5,0İstismar yokEPSS %3zarafa · webapp19 Şub 2015
- CVE-2014-003721İzleyin
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a deni
OrtaCVSS 5,0İstismar yokEPSS %2zarafa · zarafa28 Nis 2014
- CVE-2014-007921İzleyin
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions
OrtaCVSS 5,0İstismar yokEPSS %2zarafa · zarafa28 Nis 2014
- CVE-2014-01038İzleyin
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive
DüşükCVSS 2,1İstismar yokEPSS %0zarafa · webapp29 Tem 2014
- CVE-2014-54488İzleyin
Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by
DüşükCVSS 2,1İstismar yokEPSS %0zarafa · zarafa20 Eki 2014
- CVE-2014-54498İzleyin
Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sen
DüşükCVSS 2,1İstismar yokEPSS %0zarafa · webaccess20 Eki 2014
- CVE-2014-54478İzleyin
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive informa
DüşükCVSS 2,1İstismar yokEPSS %0zarafa · webapp20 Eki 2014