7.8
CVSSv2

CVE-2008-5620

Published: 17/12/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

RoundCube Webmail (roundcubemail) prior to 0.2-beta allows remote malicious users to cause a denial of service (memory consumption) via crafted size parameters that are used to create a large quota image.

Vulnerable Product Search on Vulmon Subscribe to Product

roundcube webmail 0.1

roundcube webmail

roundcube webmail 0.1.1

roundcube webmail 0.2

Vendor Advisories

Debian Bug report logs - #509596 roundcube: CVE-2008-5620 massive memory consumption via crafted image Package: roundcube; Maintainer for roundcube is Debian Roundcube Maintainers <pkg-roundcube-maintainers@listsaliothdebianorg>; Source for roundcube is src:roundcube (PTS, buildd, popcon) Reported by: Nico Golde <nion@ ...
Debian Bug report logs - #514179 CVE-2009-0413: possible XSS issue Package: roundcube; Maintainer for roundcube is Debian Roundcube Maintainers <pkg-roundcube-maintainers@listsaliothdebianorg>; Source for roundcube is src:roundcube (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Da ...