Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
horde groupware vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-0579
Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition prior to 1.0, and Groupware prior to 1.0, allows remote malicious users to include certain files via unspecified vectors. NOTE: some of these details are obtained from third party information.
Horde Groupware 1.0 Rc3
Horde Groupware 1.0 Rc2
5.4
CVSSv3
CVE-2017-16907
In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action.
Horde Groupware 5.2.21
Horde Groupware 5.2.19
NA
CVE-2008-7219
Horde Kronolith H3 2.1 prior to 2.1.7 and 2.2 prior to 2.2-RC2; Nag H3 2.1 prior to 2.1.4 and 2.2 prior to 2.2-RC2; Mnemo H3 2.1 prior to 2.1.2 and H3 2.2 prior to 2.2-RC2; Groupware 1.0 prior to 1.0.3 and 1.1 prior to 1.1-RC2; and Groupware Webmail Edition 1.0 prior to 1.0.4 and...
Horde Kronolith H3 2.1.3
Horde Kronolith H3 2.1.6
Horde Nag H3 2.1
Horde Groupware 1.0
Horde Groupware 1.0.2
Horde Nag H3 2.1.2
Horde Nag H3 2.1.3
Horde Nag H3 2.2
Horde Mnemo H3 2.1
Horde Kronolith H3 2.1.4
Horde Kronolith H3 2.1
Horde Kronolith H3 2.1.2
Horde Kronolith H3 2.1.5
Horde Groupware 1.1
Horde Mnemo H3 2.1.1
Horde Groupware Webmail Edition 1.1
Horde Groupware Webmail Edition 1.0
Horde Groupware Webmail Edition 1.0.2
Horde Kronolith H3 2.1.1
Horde Kronolith H3 2.2
Horde Nag H3 2.1.1
Horde Mnemo H3 2.2
NA
CVE-2008-1974
Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote malicious users to inject arbitrary web script or HTML via the url parameter.
Horde Groupware 1.0.5
Horde Groupware Webmail Edition 1.0.6
1 EDB exploit
NA
CVE-2012-0209
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote malicious u...
Horde Groupware 1.2.10
Horde Horde 3.3.12
1 EDB exploit
NA
CVE-2008-7218
Unspecified vulnerability in the Horde API in Horde 3.1 prior to 3.1.6 and 3.2 prior to 3.2 prior to 3.2-RC2; Turba H3 2.1 prior to 2.1.6 and 2.2 prior to 2.2-RC2; Kronolith H3 2.1 prior to 2.1.7 and H3 2.2 prior to 2.2-RC2; Nag H3 2.1 prior to 2.1.4 and 2.2 prior to 2.2-RC2; Mne...
Horde Kronolith H3 2.1.1
Horde Kronolith H3 2.1
Horde Kronolith H3 2.1.2
Horde Turba H3 2.1.1
Horde Turba H3 2.1
Horde Nag H3 2.1.2
Horde Nag H3 2.1.3
Horde Groupware 1.1
Horde Horde 3.1.1
Horde Horde 3.1.2
Horde Kronolith H3 2.1.5
Horde Kronolith H3 2.1.6
Horde Turba H3 2.1.4
Horde Turba H3 2.2
Horde Mnemo H3 2.1.1
Horde Mnemo H3 2.2
Horde Groupware Webmail Edition 1.1
Horde Horde 3.1.5
Horde Groupware Webmail Edition 1.0
Horde Horde 3.1
Horde Kronolith H3 2.1.3
Horde Kronolith H3 2.1.4
6.1
CVSSv3
CVE-2016-2228
Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware prior to 5.2.12 and Horde Groupware Webmail Edition prior to 5.2.12 allows remote malicious users to inject arbitrary web script or HTML via the searchfield parameter, as demon...
Debian Debian Linux 8.0
Horde Groupware
Horde Horde Groupware
Fedoraproject Fedora 22
Fedoraproject Fedora 23
6.1
CVSSv3
CVE-2020-8034
Gollem prior to 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting breadcrumb output. An attacker can obtain acces...
Horde Gollem
Horde Groupware 5.2.22
NA
CVE-2008-0807
lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x prior to 2.1.7 and 2.2.x prior to 2.2-RC3, as used in products such as Horde Groupware prior to 1.0.4 and Horde Groupware Webmail Edition prior to 1.0.5, does not properly check access rights, which allows remote aut...
Horde Groupware 1.0.3
Horde Groupware Webmail Edition 1.0.4
Horde Turba Contact Manager 2.1.6
6.1
CVSSv3
CVE-2020-8035
The image view functionality in Horde Groupware Webmail Edition prior to 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an SVG image upload containing a JavaScript payload. An attacker can obtain access to a victim's webmail account by making the...
Horde Groupware
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33228
CVE-2024-20361
log injection
bypass
CVE-2024-4985
CVE-2024-35223
CVE-2024-29849
CVE-2024-31893
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »