Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zimbra collaboration suite vulnerabilities and exploits
(subscribe to this query)
757
VMScore
CVE-2019-9670
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x prior to 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
Synacor Zimbra Collaboration Suite 8.7.11
Synacor Zimbra Collaboration Suite
1 EDB exploit
7 Github repositories
694
VMScore
CVE-2022-27925
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
Zimbra Collaboration 9.0.0
Zimbra Collaboration 8.8.15
1 Metasploit module
13 Github repositories
1 Article
668
VMScore
CVE-2021-35209
An issue exists in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 prior to 8.8.15 Patch 23 and 9.x prior to 9.0.0 Patch 16. The value of the X-Host header overwrites the value of the Host header in proxied requests. The value of X-Host header is not che...
Zimbra Collaboration 9.0.0
Zimbra Collaboration 8.8.15
Zimbra Collaboration
668
VMScore
CVE-2019-6980
Synacor Zimbra Collaboration Suite 8.7.x up to and including 8.8.11 allows insecure object deserialization in the IMAP component.
Synacor Zimbra Collaboration Suite 8.7.11
Synacor Zimbra Collaboration Suite
Synacor Zimbra Collaboration Suite 8.8.11
Synacor Zimbra Collaboration Suite 8.8.10
Synacor Zimbra Collaboration Suite 8.8.9
668
VMScore
CVE-2018-20160
ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XXE attacks, as demonstrated by a crafted XML request to mailboxd.
Synacor Zimbra Collaboration Suite 8.7.11
Synacor Zimbra Collaboration Suite
Synacor Zimbra Collaboration Suite 8.8.11
Synacor Zimbra Collaboration Suite 8.8.10
Synacor Zimbra Collaboration Suite 8.8.9
668
VMScore
CVE-2017-6813
A service provided by Zimbra Collaboration Suite (ZCS) prior to 8.7.6 fails to require needed privileges before performing a few requested operations.
Synacor Zimbra Collaboration Suite
668
VMScore
CVE-2017-6821
Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) prior to 8.7.6 allows malicious users to have unspecified impact via unknown vectors.
Synacor Zimbra Collaboration Suite
668
VMScore
CVE-2016-9924
Zimbra Collaboration Suite (ZCS) prior to 8.7.4 allows remote malicious users to conduct XML External Entity (XXE) attacks.
Synacor Zimbra Collaboration Suite
605
VMScore
CVE-2020-7796
Zimbra Collaboration Suite (ZCS) prior to 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.
Synacor Zimbra Collaboration Suite 8.8.15
Synacor Zimbra Collaboration Suite
605
VMScore
CVE-2015-7610
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) prior to 8.6.0 Patch 10, 8.7.x prior to 8.7.11 Patch 2, and 8.8.x prior to 8.8.8 Patch 1 allows remote malicious users to hijack the authentication of unspecified victims by ...
Zimbra Zimbra Collaboration Suite 8.6.0
Synacor Zimbra Collaboration Suite 8.7.11
Synacor Zimbra Collaboration Suite 8.6.0
Synacor Zimbra Collaboration Suite
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4541
CVE-2024-3080
CVE-2024-4787
log injection
CVE-2024-5967
inject
CVE-2024-30078
CVE-2024-5899
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »