Product:

Zimbra_collaboration_suite

(Synacor)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 63
Date Id Summary Products Score Patch Annotated
2020-07-02 CVE-2020-13653 An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user's profile. The injected code can be reflected and executed when changing an e-mail signature. Zimbra_collaboration_suite 6.1
2021-12-15 CVE-2020-18984 A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a host header injection. Zimbra_collaboration_suite 6.1
2021-12-15 CVE-2020-18985 An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing. Zimbra_collaboration_suite 6.1
2018-10-03 CVE-2018-17938 Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value. Zimbra_collaboration_suite 5.3
2018-05-10 CVE-2018-10949 mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors. Zimbra_collaboration_suite 5.3
2018-05-10 CVE-2018-10951 mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API. Zimbra_collaboration_suite, Zimbra_collaboration_suite 6.5
2018-05-30 CVE-2018-10939 Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group. Zimbra_collaboration_suite, Zimbra_collaboration_suite 6.1
2017-05-23 CVE-2017-7288 Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Zimbra_collaboration_suite 6.1
2017-05-23 CVE-2017-6821 Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors. Zimbra_collaboration_suite 9.8
2017-05-23 CVE-2017-6813 A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations. Zimbra_collaboration_suite 9.8