Search CVE reports


Toggle filters

11 – 20 of 50 results


CVE-2018-8741

Medium priority
Fixed

A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail Not in release
Show less packages

CVE-2017-7692

Medium priority

Some fixes available 3 of 4

SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mishandled in a popen call. It's possible to exploit this vulnerability to execute...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2017-5181

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7692. Reason: This candidate is a reservation duplicate of CVE-2017-7692. Notes: All CVE users should reference CVE-2017-7692 instead of this candidate. All...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2012-2124

Low priority
Not affected

functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption)...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2011-2753

Medium priority
Ignored

Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of unspecified victims via vectors involving (1) the empty trash implementation and...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2011-2752

Low priority
Ignored

CRLF injection vulnerability in SquirrelMail 1.4.21 and earlier allows remote attackers to modify or add preference values via a \n (newline) character, a different vulnerability than CVE-2010-4555.

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2011-2023

Low priority
Ignored

Cross-site scripting (XSS) vulnerability in functions/mime.php in SquirrelMail before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via a crafted STYLE element in an e-mail message.

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2010-4555

Low priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) drop-down selection lists, (2) the > (greater than)...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2010-4554

Low priority
Ignored

functions/page_header.php in SquirrelMail 1.4.21 and earlier does not prevent page rendering inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2010-2813

Low priority
Ignored

functions/imap_general.php in SquirrelMail before 1.4.21 does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages