Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Zimbra_collaboration_suite
(Synacor)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 63 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-07-02 | CVE-2020-13653 | An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user's profile. The injected code can be reflected and executed when changing an e-mail signature. | Zimbra_collaboration_suite | 6.1 | ||
2021-12-15 | CVE-2020-18984 | A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a host header injection. | Zimbra_collaboration_suite | 6.1 | ||
2021-12-15 | CVE-2020-18985 | An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing. | Zimbra_collaboration_suite | 6.1 | ||
2018-10-03 | CVE-2018-17938 | Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value. | Zimbra_collaboration_suite | 5.3 | ||
2018-05-10 | CVE-2018-10949 | mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors. | Zimbra_collaboration_suite | 5.3 | ||
2018-05-10 | CVE-2018-10951 | mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API. | Zimbra_collaboration_suite, Zimbra_collaboration_suite | 6.5 | ||
2018-05-30 | CVE-2018-10939 | Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group. | Zimbra_collaboration_suite, Zimbra_collaboration_suite | 6.1 | ||
2017-05-23 | CVE-2017-7288 | Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Zimbra_collaboration_suite | 6.1 | ||
2017-05-23 | CVE-2017-6821 | Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors. | Zimbra_collaboration_suite | 9.8 | ||
2017-05-23 | CVE-2017-6813 | A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations. | Zimbra_collaboration_suite | 9.8 |