Search CVE reports


Toggle filters

31 – 40 of 76 results


CVE-2019-10740

Medium priority
Vulnerable

In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-9846

Medium priority
Vulnerable

In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-19206

Medium priority
Vulnerable

steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-19205

Medium priority
Vulnerable

Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-1000071

Medium priority
Vulnerable

roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2017-8114

Medium priority
Vulnerable

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-6820

Medium priority
Vulnerable

rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-16651

High priority

Some fixes available 1 of 3

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-1000049

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8864. Reason: This candidate is a reservation duplicate of CVE-2015-8864. Notes: All CVE users should reference CVE-2015-8864 instead of this candidate. ...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube
Show less packages

CVE-2016-9920

Medium priority
Vulnerable

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail...

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Not affected Not affected Not affected Not affected
Show less packages