Summary
Detail | |||
---|---|---|---|
Vendor | Roundcube | First view | 2005-12-19 |
Product | Webmail | Last view | 2020-08-12 |
Version | Type | Application | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
Related : CVE
Date | Alert | Description | |
---|---|---|---|
6.1 | 2020-08-12 | CVE-2020-16145 | Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15. |
6.1 | 2020-07-06 | CVE-2020-15562 | An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists. |
6.1 | 2020-06-09 | CVE-2020-13965 | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. |
6.1 | 2020-06-09 | CVE-2020-13964 | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object. |
9.8 | 2020-05-04 | CVE-2020-12641 | rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path. |
9.8 | 2020-05-04 | CVE-2020-12640 | Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php. |
6.5 | 2020-05-04 | CVE-2020-12626 | An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered. |
6.1 | 2020-05-04 | CVE-2020-12625 | An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message. |
7.4 | 2019-08-19 | CVE-2019-15237 | Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks. |
4.3 | 2019-04-07 | CVE-2019-10740 | In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker. |
5.9 | 2018-05-16 | CVE-2017-17688 | ** DISPUTED ** The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification. |
8.8 | 2018-04-07 | CVE-2018-9846 | In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after a %0d%0a sequence. NOTE: this is less easily exploitable in 1.3.4 and later because of a Same Origin Policy protection mechanism. |
7.5 | 2018-03-13 | CVE-2018-1000071 | roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity. |
7.8 | 2017-11-09 | CVE-2017-16651 | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests. |
7.5 | 2017-05-23 | CVE-2015-5383 | Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory. |
6.5 | 2017-05-23 | CVE-2015-5382 | program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard. |
6.1 | 2017-05-23 | CVE-2015-5381 | Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI. |
8.8 | 2017-04-29 | CVE-2017-8114 | Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin. |
6.1 | 2017-04-13 | CVE-2016-4068 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864. |
6.1 | 2017-04-13 | CVE-2015-8864 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068. |
6.1 | 2017-03-12 | CVE-2017-6820 | rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element. |
8.8 | 2017-01-30 | CVE-2015-2181 | Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username. |
8.8 | 2017-01-30 | CVE-2015-2180 | The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password. |
6.1 | 2016-12-20 | CVE-2016-4552 | Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message. |
7.5 | 2016-12-08 | CVE-2016-9920 | steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
47% (23) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
10% (5) | CWE-352 | Cross-Site Request Forgery (CSRF) |
8% (4) | CWE-200 | Information Exposure |
6% (3) | CWE-20 | Improper Input Validation |
4% (2) | CWE-399 | Resource Management Errors |
4% (2) | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path ... |
2% (1) | CWE-732 | Incorrect Permission Assignment for Critical Resource |
2% (1) | CWE-552 | Files or Directories Accessible to External Parties |
2% (1) | CWE-284 | Access Control (Authorization) Issues |
2% (1) | CWE-269 | Improper Privilege Management |
2% (1) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
2% (1) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
2% (1) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
2% (1) | CWE-88 | Argument Injection or Modification |
2% (1) | CWE-74 | Failure to Sanitize Data into a Different Plane ('Injection') |
Oval Markup Language : Definitions
OvalID | Name |
---|---|
oval:org.mitre.oval:def:19395 | DSA-2787-1 roundcube - design error |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
77047 | Roundcube Webmail include/iniset.php Subject Header Parsing Remote DoS |
74567 | RoundCube Webmail Multiple Unspecified Script _mbox Parameter XSS |
73871 | Roundcube Webmail Login Form Email Message Composition Remote Information Dis... |
73870 | Roundcube Webmail steps/utils/modcss.inc External CSS Request Remote Informat... |
62104 | Roundcube E-mail Message DNS Prefetching Weakness |
60567 | RoundCube Webmail Arbitrary Email Send Unspecified CSRF |
59661 | RoundCube Webmail User Information Modification CSRF |
53893 | Mahara html2text HTML To Plain Text Conversion Arbitrary Code Execution |
51505 | RoundCube Webmail HTML Background Attribute XSS |
50879 | RoundCube Webmail Crafted Quota Image Size Parameter Memory Consumption DoS |
50694 | RoundCube Webmail bin/html2text.php preg_replace Function Remote PHP Code Exe... |
44117 | RoundCube Webmail Style Sheet Expression Commands XSS |
22113 | RoundCube Webmail _task Variable Path Disclosure |
ExploitDB Exploits
id | Description |
---|---|
7553 | RoundCube Webmail <= 0.2b Remote Code Execution Exploit |
7549 | RoundCube Webmail <= 0.2-3 beta Code Execution Vulnerability |
OpenVAS Exploits
id | Description |
---|---|
2012-08-30 | Name : FreeBSD Ports: roundcube File : nvt/freebsd_roundcube2.nasl |
2012-08-30 | Name : Fedora Update for roundcubemail FEDORA-2012-12362 File : nvt/gb_fedora_2012_12362_roundcubemail_fc17.nasl |
2012-08-30 | Name : Fedora Update for roundcubemail FEDORA-2012-12357 File : nvt/gb_fedora_2012_12357_roundcubemail_fc16.nasl |
2012-06-25 | Name : Fedora Update for roundcubemail FEDORA-2012-9337 File : nvt/gb_fedora_2012_9337_roundcubemail_fc16.nasl |
2012-06-25 | Name : Fedora Update for roundcubemail FEDORA-2012-9329 File : nvt/gb_fedora_2012_9329_roundcubemail_fc15.nasl |
2012-02-06 | Name : Mac OS X Multiple Vulnerabilities (2012-001) File : nvt/gb_macosx_su12-001.nasl |
2011-09-21 | Name : FreeBSD Ports: roundcube File : nvt/freebsd_roundcube1.nasl |
2010-03-02 | Name : Mandriva Update for roundcubemail MDVSA-2010:048 (roundcubemail) File : nvt/gb_mandriva_MDVSA_2010_048.nasl |
2010-03-02 | Name : Fedora Update for roundcubemail FEDORA-2010-1399 File : nvt/gb_fedora_2010_1399_roundcubemail_fc11.nasl |
2010-03-02 | Name : Fedora Update for roundcubemail FEDORA-2010-1385 File : nvt/gb_fedora_2010_1385_roundcubemail_fc12.nasl |
2010-02-08 | Name : Mandriva Update for gtk MDVA-2010:048 (gtk) File : nvt/gb_mandriva_MDVA_2010_048.nasl |
2010-01-20 | Name : Mandriva Update for roundcubemail MDVSA-2010:015 (roundcubemail) File : nvt/gb_mandriva_MDVSA_2010_015.nasl |
2009-12-10 | Name : Fedora Core 10 FEDORA-2009-12481 (roundcubemail) File : nvt/fcore_2009_12481.nasl |
2009-06-30 | Name : Ubuntu USN-791-1 (moodle) File : nvt/ubuntu_791_1.nasl |
2009-06-05 | Name : Ubuntu USN-698-1 (nagios) File : nvt/ubuntu_698_1.nasl |
2009-03-20 | Name : FreeBSD Ports: roundcube File : nvt/freebsd_roundcube0.nasl |
2009-02-17 | Name : Fedora Update for roundcubemail FEDORA-2008-5342 File : nvt/gb_fedora_2008_5342_roundcubemail_fc8.nasl |
2009-02-17 | Name : Fedora Update for roundcubemail FEDORA-2008-5333 File : nvt/gb_fedora_2008_5333_roundcubemail_fc9.nasl |
2009-02-17 | Name : Fedora Update for roundcubemail FEDORA-2008-5315 File : nvt/gb_fedora_2008_5315_roundcubemail_fc7.nasl |
2009-02-13 | Name : Fedora Update for roundcubemail FEDORA-2008-11581 File : nvt/gb_fedora_2008_11581_roundcubemail_fc8.nasl |
2009-02-13 | Name : Fedora Update for roundcubemail FEDORA-2008-11535 File : nvt/gb_fedora_2008_11535_roundcubemail_fc9.nasl |
2009-02-13 | Name : Fedora Update for roundcubemail FEDORA-2008-11456 File : nvt/gb_fedora_2008_11456_roundcubemail_fc10.nasl |
2009-02-13 | Name : Fedora Update for roundcubemail FEDORA-2008-11234 File : nvt/gb_fedora_2008_11234_roundcubemail_fc9.nasl |
2009-02-13 | Name : Fedora Update for roundcubemail FEDORA-2008-11220 File : nvt/gb_fedora_2008_11220_roundcubemail_fc8.nasl |
2009-02-10 | Name : Fedora Core 9 FEDORA-2009-1256 (roundcubemail) File : nvt/fcore_2009_1256.nasl |
Snort® IPS/IDS
Date | Description |
---|---|
2018-09-11 | RoundCube WebMail IMAP command injection attempt RuleID : 47510 - Type : SERVER-WEBAPP - Revision : 3 |
2018-09-11 | RoundCube WebMail IMAP command injection attempt RuleID : 47509 - Type : SERVER-WEBAPP - Revision : 2 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2019-01-03 | Name: The remote Fedora host is missing a security update. File: fedora_2018-c279b3696f.nasl - Type: ACT_GATHER_INFO |
2019-01-03 | Name: The remote Fedora host is missing a security update. File: fedora_2018-77fe2e20ad.nasl - Type: ACT_GATHER_INFO |
2018-05-29 | Name: The remote Fedora host is missing a security update. File: fedora_2018-6020628437.nasl - Type: ACT_GATHER_INFO |
2018-05-29 | Name: The remote Fedora host is missing a security update. File: fedora_2018-25525a9346.nasl - Type: ACT_GATHER_INFO |
2018-04-30 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-4181.nasl - Type: ACT_GATHER_INFO |
2018-04-23 | Name: The remote Fedora host is missing a security update. File: fedora_2018-f6dc921a19.nasl - Type: ACT_GATHER_INFO |
2018-04-23 | Name: The remote Fedora host is missing a security update. File: fedora_2018-57fbdb1cb5.nasl - Type: ACT_GATHER_INFO |
2018-04-16 | Name: The remote FreeBSD host is missing a security-related update. File: freebsd_pkg_48894ca93e6f11e892f0f0def167eeea.nasl - Type: ACT_GATHER_INFO |
2018-01-15 | Name: The remote Fedora host is missing a security update. File: fedora_2017-cbc49efae8.nasl - Type: ACT_GATHER_INFO |
2017-11-28 | Name: The remote Debian host is missing a security update. File: debian_DLA-1193.nasl - Type: ACT_GATHER_INFO |
2017-11-20 | Name: The remote Fedora host is missing a security update. File: fedora_2017-1560290881.nasl - Type: ACT_GATHER_INFO |
2017-11-13 | Name: The remote FreeBSD host is missing a security-related update. File: freebsd_pkg_f622608cc53c11e7a633009c02a2ab30.nasl - Type: ACT_GATHER_INFO |
2017-11-10 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-4030.nasl - Type: ACT_GATHER_INFO |
2017-07-17 | Name: The remote Fedora host is missing a security update. File: fedora_2017-7263e7d321.nasl - Type: ACT_GATHER_INFO |
2017-07-10 | Name: The remote Gentoo host is missing one or more security-related patches. File: gentoo_GLSA-201707-11.nasl - Type: ACT_GATHER_INFO |
2017-06-12 | Name: The remote FreeBSD host is missing a security-related update. File: freebsd_pkg_bce47c894d3f11e78080a4badb2f4699.nasl - Type: ACT_GATHER_INFO |
2017-05-16 | Name: The remote openSUSE host is missing a security update. File: openSUSE-2017-580.nasl - Type: ACT_GATHER_INFO |
2017-05-09 | Name: The remote Fedora host is missing a security update. File: fedora_2017-ede53aa845.nasl - Type: ACT_GATHER_INFO |
2017-05-09 | Name: The remote Fedora host is missing a security update. File: fedora_2017-c8448d0cad.nasl - Type: ACT_GATHER_INFO |
2017-05-08 | Name: The remote Debian host is missing a security update. File: debian_DLA-933.nasl - Type: ACT_GATHER_INFO |
2017-03-20 | Name: The remote openSUSE host is missing a security update. File: openSUSE-2017-355.nasl - Type: ACT_GATHER_INFO |
2017-03-14 | Name: The remote Debian host is missing a security update. File: debian_DLA-855.nasl - Type: ACT_GATHER_INFO |
2016-12-27 | Name: The remote Gentoo host is missing one or more security-related patches. File: gentoo_GLSA-201612-44.nasl - Type: ACT_GATHER_INFO |
2016-12-14 | Name: The remote Fedora host is missing a security update. File: fedora_2016-b4896f20b3.nasl - Type: ACT_GATHER_INFO |
2016-12-14 | Name: The remote Fedora host is missing a security update. File: fedora_2016-60753c3dcd.nasl - Type: ACT_GATHER_INFO |