Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
synacor zimbra collaboration suite vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2016-3404
Unspecified vulnerability in Zimbra Collaboration prior to 8.7.0 allows remote malicious users to affect integrity via unknown vectors, aka bug 103959.
Synacor Zimbra Collaboration Suite
8.8
CVSSv3
CVE-2016-3406
Multiple cross-site request forgery (CSRF) vulnerabilities in Zimbra Collaboration prior to 8.7.0 allow remote malicious users to hijack the authentication of unspecified victims via vectors involving (1) the Client uploader extension or (2) extension REST handlers, aka bugs 1042...
Synacor Zimbra Collaboration Suite
6.1
CVSSv3
CVE-2016-3410
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration prior to 8.7.0 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors, aka bugs 103956, 103995, 104475, 104838, and 104839.
Synacor Zimbra Collaboration Suite
9.8
CVSSv3
CVE-2016-9924
Zimbra Collaboration Suite (ZCS) prior to 8.7.4 allows remote malicious users to conduct XML External Entity (XXE) attacks.
Synacor Zimbra Collaboration Suite
9.8
CVSSv3
CVE-2017-6813
A service provided by Zimbra Collaboration Suite (ZCS) prior to 8.7.6 fails to require needed privileges before performing a few requested operations.
Synacor Zimbra Collaboration Suite
9.8
CVSSv3
CVE-2017-6821
Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) prior to 8.7.6 allows malicious users to have unspecified impact via unknown vectors.
Synacor Zimbra Collaboration Suite
6.1
CVSSv3
CVE-2015-7609
Synacor Zimbra Mail Client 8.6 prior to 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra.
Synacor Zimbra Collaboration Suite 8.6.0
6.1
CVSSv3
CVE-2020-18984
A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated malicious users to execute arbitrary web scripts or HTML via a host header injection.
Synacor Zimbra Collaboration Suite 8.8.12
6.1
CVSSv3
CVE-2020-18985
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows malicious users to redirect users to any arbitrary website of their choosing.
Synacor Zimbra Collaboration Suite 8.8.12
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5