Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

41 – 50 of 71 results


CVE-2015-2181

Medium priority
Ignored

Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2015-2180

Medium priority
Ignored

The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2016-4552

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message.

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2016-9920

Medium priority
Vulnerable

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail...

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-4069

Medium priority
Vulnerable

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service...

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2015-8794

Medium priority
Ignored

Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter,...

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2015-8793

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter in a mail task to the...

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2015-8770

Medium priority
Ignored

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary...

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2015-8105

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name in a drag-n-drop file upload.

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2015-1433

Medium priority
Ignored

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages