Search CVE reports


Toggle filters

21 – 30 of 50 results


CVE-2010-1637

Low priority

Some fixes available 4 of 5

The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2009-2964

Medium priority

Some fixes available 4 of 5

Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hijack the authentication of unspecified victims via features such as send message...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2009-1381

Medium priority

Some fixes available 3 of 4

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2009-1581

Low priority

Some fixes available 3 of 4

functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2009-1580

Medium priority

Some fixes available 3 of 4

Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2009-1579

Medium priority

Some fixes available 3 of 4

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2009-1578

Medium priority

Some fixes available 3 of 4

Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2009-0030

Low priority
Not affected

A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in...

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2008-2379

Medium priority
Fixed

Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages

CVE-2008-3663

Low priority

Some fixes available 3 of 4

Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

1 affected package

squirrelmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squirrelmail
Show less packages