Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
horde horde groupware vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-2783
Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote malicious users to inject arbitrary web script or HTML via the timestamp parameter to (1) week.php, (2) workweek.php, and (3) day.php; and (4) the horde p...
Horde Kronolith
Horde Groupware
Horde Groupware Webmail Edition
3 EDB exploits
NA
CVE-2008-7218
Unspecified vulnerability in the Horde API in Horde 3.1 prior to 3.1.6 and 3.2 prior to 3.2 prior to 3.2-RC2; Turba H3 2.1 prior to 2.1.6 and 2.2 prior to 2.2-RC2; Kronolith H3 2.1 prior to 2.1.7 and H3 2.2 prior to 2.2-RC2; Nag H3 2.1 prior to 2.1.4 and 2.2 prior to 2.2-RC2; Mne...
Horde Nag H3 2.1.3
Horde Horde 3.2
Horde Groupware 1.1
Horde Horde 3.1.4
Horde Groupware Webmail Edition 1.1
Horde Nag H3 2.1.2
Horde Groupware 1.0
Horde Turba H3 2.2
Horde Nag H3 2.1.1
Horde Turba H3 2.1.1
Horde Nag H3 2.2
Horde Turba H3 2.1.4
Horde Horde 3.1.5
Horde Turba H3 2.1.5
Horde Kronolith H3 2.1.5
Horde Groupware 1.0.2
Horde Groupware Webmail Edition 1.0.3
Horde Mnemo H3 2.1.1
Horde Mnemo H3 2.1
Horde Kronolith H3 2.1.2
Horde Kronolith H3 2.1.4
Horde Groupware 1.0.1
5.4
CVSSv3
CVE-2017-16907
In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action.
Horde Groupware 5.2.21
Horde Groupware 5.2.19
NA
CVE-2012-0209
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote malicious u...
Horde Horde 3.3.12
Horde Groupware 1.2.10
1 EDB exploit
NA
CVE-2008-0807
lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x prior to 2.1.7 and 2.2.x prior to 2.2-RC3, as used in products such as Horde Groupware prior to 1.0.4 and Horde Groupware Webmail Edition prior to 1.0.5, does not properly check access rights, which allows remote aut...
Horde Groupware 1.0.3
Horde Groupware Webmail Edition 1.0.4
Horde Turba Contact Manager 2.1.6
NA
CVE-2008-1974
Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote malicious users to inject arbitrary web script or HTML via the url parameter.
Horde Groupware 1.0.5
Horde Groupware Webmail Edition 1.0.6
1 EDB exploit
NA
CVE-2007-0579
Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition prior to 1.0, and Groupware prior to 1.0, allows remote malicious users to include certain files via unspecified vectors. NOTE: some of these details are obtained from third party information.
Horde Groupware 1.0 Rc3
Horde Groupware 1.0 Rc2
NA
CVE-2009-0931
Cross-site scripting (XSS) vulnerability in the tag cloud search script (horde/services/portal/cloud_search.php) in Horde prior to 3.2.4 and 3.3.3, and Horde Groupware prior to 1.1.5, allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Debian Horde
Debian Horde Groupware
Debian Horde 3.2.2
Debian Horde 3.2.3
Debian Horde 3.3
NA
CVE-2007-6018
IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote malicious users to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" delet...
Horde Horde 3.1.5
Horde Framework 3.1.5
Horde Groupware Webmail Edition 1.0.3
Horde Imp 4.1.5
6.1
CVSSv3
CVE-2016-2228
Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware prior to 5.2.12 and Horde Groupware Webmail Edition prior to 5.2.12 allows remote malicious users to inject arbitrary web script or HTML via the searchfield parameter, as demon...
Debian Debian Linux 8.0
Horde Horde Groupware
Horde Groupware
Fedoraproject Fedora 22
Fedoraproject Fedora 23
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-6280
CVE-2024-5346
CVE-2024-30078
CVE-2022-45803
CVE-2024-36886
SQL
CVE-2024-24553
IMAP
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »