Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

51 – 60 of 71 results


CVE-2014-9587

Medium priority
Ignored

Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or...

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2013-1904

Medium priority
Ignored

Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the...

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected
Show less packages

CVE-2013-6172

Medium priority
Ignored

steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL...

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected
Show less packages

CVE-2013-5646

Medium priority
Not affected

Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube
Show less packages

CVE-2013-5645

Medium priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode,...

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected
Show less packages

CVE-2012-6121

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected
Show less packages

CVE-2012-4668

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the signature in an email.

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2012-3508

Low priority
Ignored

Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script or HTML by using "javascript:" in an href attribute in the body of an...

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube Not affected Not affected
Show less packages

CVE-2012-3507

Low priority
Not affected

Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject.

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube
Show less packages

CVE-2012-1253

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment.

1 affected packages

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
roundcube
Show less packages