VYPR

Vendor CVEs

Zimbra

All CVEs

139 total · sorted by risk
  • CVE-2022-41348Oct 12, 2022
    risk 0.00cvss epss 0.00

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, leading to information disclosure.

  • CVE-2022-41350Oct 12, 2022
    risk 0.00cvss epss 0.00

    In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.

  • CVE-2022-41349Oct 12, 2022
    risk 0.00cvss epss 0.00

    In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.

  • CVE-2022-41351Oct 12, 2022
    risk 0.00cvss epss 0.00

    In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing the value of the uncheck parameter to a string (instead of default value of 10).

  • CVE-2022-41347Sep 26, 2022
    risk 0.00cvss epss 0.00

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGINX binary as root with arbitrary parameters. As part of its intended functionality, NGINX can load a user-defined configuration…

  • CVE-2022-37393Aug 16, 2022
    risk 0.00cvss epss 0.02

    Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as…

  • CVE-2022-37044Aug 11, 2022
    risk 0.00cvss epss 0.00

    In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onload that are partially sanitised and lead to reflected XSS that allows executing arbitrary JavaScript on the victim's machine.

  • CVE-2022-37043Aug 11, 2022
    risk 0.00cvss epss 0.00

    An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attacker-controlled page, a request will be sent to the…

  • CVE-2022-37041Aug 11, 2022
    risk 0.00cvss epss 0.01

    An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-Host header overwrites the value of the Host header in proxied requests. The value of X-Forwarded-Host header is not checked…

  • CVE-2022-32294Jul 11, 2022
    risk 0.00cvss epss 0.02

    Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (aka the syslog port). NOTE: a third party reports that this cannot be reproduced.

  • CVE-2020-18985Dec 15, 2021
    risk 0.00cvss epss 0.01

    An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.

  • CVE-2020-18984Dec 15, 2021
    risk 0.00cvss epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a host header injection.

  • CVE-2021-35207Jul 2, 2021
    risk 0.00cvss epss 0.03

    An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability exists in the login component of Zimbra Web Client, in which an attacker can execute arbitrary JavaScript by adding executable JavaScript to the…

  • CVE-2021-35208Jul 2, 2021
    risk 0.00cvss epss 0.01

    An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 23. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary…

  • CVE-2021-35209Jul 2, 2021
    risk 0.00cvss epss 0.03

    An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. The value of the X-Host header overwrites the value of the Host header in proxied requests. The value of X-Host header is…

  • CVE-2021-34807Jul 2, 2021
    risk 0.00cvss epss 0.01

    An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker could…

  • CVE-2020-35123Dec 17, 2020
    risk 0.00cvss epss 0.01

    In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and…

  • CVE-2020-13653Jul 2, 2020
    risk 0.00cvss epss 0.01

    An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user's profile. The injected code can be reflected and executed when changing an e-mail…

  • CVE-2020-12846Jun 3, 2020
    risk 0.00cvss epss 0.03

    Zimbra before 8.8.15 Patch 10 and 9.x before 9.0.0 Patch 3 allows remote code execution via an avatar file. There is potential abuse of /service/upload servlet in the webmail subsystem. A user can upload executable files (exe,sh,bat,jar) in the Contact section of the mailbox as…

  • CVE-2020-11737May 5, 2020
    risk 0.00cvss epss 0.02

    A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript. The attack requires an A element containing an href attribute with a "www" substring (including…

  • CVE-2020-10194Mar 20, 2020
    risk 0.00cvss epss 0.01

    cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domain of the galsync account in the request.

  • CVE-2020-8633Feb 18, 2020
    risk 0.00cvss epss 0.01

    An issue was discovered in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. When grantors revoked a shared calendar in Outlook, the calendar stayed mounted and accessible.

  • CVE-2013-1938Feb 12, 2020
    risk 0.00cvss epss 0.03

    Zimbra 2013 has XSS in aspell.php

  • CVE-2014-8563Jan 27, 2020
    risk 0.00cvss epss 0.03

    Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.

  • CVE-2019-8945Jan 27, 2020
    risk 0.00cvss epss 0.01

    Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

  • CVE-2019-8946Jan 27, 2020
    risk 0.00cvss epss 0.01

    Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

  • CVE-2019-8947Jan 27, 2020
    risk 0.00cvss epss 0.01

    Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS.

  • CVE-2015-2249Jan 27, 2020
    risk 0.00cvss epss 0.01

    Zimbra Collaboration before 8.6.0 patch5 has XSS.

  • CVE-2014-5500Jan 27, 2020
    risk 0.00cvss epss 0.01

    Synacor Zimbra Collaboration before 8.0.8 has XSS.

  • CVE-2019-11318Jan 27, 2020
    risk 0.00cvss epss 0.01

    Zimbra Collaboration before 8.8.12 Patch 1 has persistent XSS.

  • CVE-2019-12427Jan 27, 2020
    risk 0.00cvss epss 0.01

    Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console.

  • CVE-2019-15313Jan 27, 2020
    risk 0.00cvss epss 0.01

    In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability.

  • CVE-2019-6981May 29, 2019
    risk 0.00cvss epss 0.01

    Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component.

  • CVE-2018-20160May 29, 2019
    risk 0.00cvss epss 0.02

    ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XXE attacks, as demonstrated by a crafted XML request to mailboxd.

  • CVE-2013-7217Dec 26, 2013
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impact and unspecified vectors, a different vulnerability than CVE-2013-7091.

  • CVE-2013-5119Sep 23, 2013
    risk 0.00cvss epss 0.01

    Zimbra Collaboration Suite (ZCS) 6.0.16 and earlier allows man-in-the-middle attackers to obtain access by sniffing the network and replaying the ZM_AUTH_TOKEN token.

  • CVE-2012-0903Jan 20, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name.

  • CVE-2008-1226Mar 10, 2008
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration Suite (ZCS) 4.0.3, 4.5.6, and possibly other versions before 4.5.10 allow remote attackers to inject arbitrary web script or HTML via an e-mail attachment, possibly involving a (1) .jpg or (2) .gif image…

  • CVE-2007-0284Jan 17, 2007
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2, have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J03 and (2) OC4J04.

Page 3 of 3