This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Roundcube First view 2012-06-04
Product Webmail Last view 2021-11-19
Version 0.6 Type Application
Update beta  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:roundcube:webmail

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
9.8 2021-11-19 CVE-2021-44026

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

6.1 2021-11-19 CVE-2021-44025

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

5.4 2021-06-24 CVE-2020-18671

Cross Site Scripting (XSS) vulnerability in Roundcube Mail <=1.4.4 via smtp config in /installer/test.php.

5.4 2021-02-09 CVE-2021-26925

Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.

6.1 2020-12-28 CVE-2020-35730

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

6.1 2020-08-12 CVE-2020-16145

Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

6.1 2020-07-06 CVE-2020-15562

An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.

6.1 2020-06-09 CVE-2020-13965

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

6.1 2020-06-09 CVE-2020-13964

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.

9.8 2020-05-04 CVE-2020-12641

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

9.8 2020-05-04 CVE-2020-12640

Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

6.5 2020-05-04 CVE-2020-12626

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.

6.1 2020-05-04 CVE-2020-12625

An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.

7.4 2019-08-19 CVE-2019-15237

Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.

4.3 2019-04-07 CVE-2019-10740

In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.

6.1 2018-11-12 CVE-2018-19206

steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of

7.5 2018-11-12 CVE-2018-19205

Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.

8.8 2018-04-07 CVE-2018-9846

In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after a %0d%0a sequence. NOTE: this is less easily exploitable in 1.3.4 and later because of a Same Origin Policy protection mechanism.

7.5 2018-03-13 CVE-2018-1000071

roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.

7.8 2017-11-09 CVE-2017-16651

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

8.8 2017-04-29 CVE-2017-8114

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

6.1 2017-04-13 CVE-2016-4068

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.

6.1 2017-04-13 CVE-2015-8864

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.

6.1 2017-03-12 CVE-2017-6820

rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.

8.8 2017-01-30 CVE-2015-2181

Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.

CWE : Common Weakness Enumeration

%idName
55% (21) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
7% (3) CWE-352 Cross-Site Request Forgery (CSRF)
5% (2) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...
5% (2) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...
2% (1) CWE-732 Incorrect Permission Assignment for Critical Resource
2% (1) CWE-552 Files or Directories Accessible to External Parties
2% (1) CWE-319 Cleartext Transmission of Sensitive Information
2% (1) CWE-284 Access Control (Authorization) Issues
2% (1) CWE-269 Improper Privilege Management
2% (1) CWE-200 Information Exposure
2% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
2% (1) CWE-78 Improper Sanitization of Special Elements used in an OS Command ('O...
2% (1) CWE-74 Failure to Sanitize Data into a Different Plane ('Injection')
2% (1) CWE-20 Improper Input Validation

OpenVAS Exploits

id Description
2012-08-30 Name : Fedora Update for roundcubemail FEDORA-2012-12357
File : nvt/gb_fedora_2012_12357_roundcubemail_fc16.nasl
2012-08-30 Name : Fedora Update for roundcubemail FEDORA-2012-12362
File : nvt/gb_fedora_2012_12362_roundcubemail_fc17.nasl
2012-06-25 Name : Fedora Update for roundcubemail FEDORA-2012-9329
File : nvt/gb_fedora_2012_9329_roundcubemail_fc15.nasl
2012-06-25 Name : Fedora Update for roundcubemail FEDORA-2012-9337
File : nvt/gb_fedora_2012_9337_roundcubemail_fc16.nasl

Snort® IPS/IDS

Date Description
2019-10-01 Roundcube webmail cross-site-scripting attempt
RuleID : 51378 - Type : SERVER-WEBAPP - Revision : 1
2018-09-11 RoundCube WebMail IMAP command injection attempt
RuleID : 47510 - Type : SERVER-WEBAPP - Revision : 3
2018-09-11 RoundCube WebMail IMAP command injection attempt
RuleID : 47509 - Type : SERVER-WEBAPP - Revision : 2

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2019-01-03 Name: The remote Fedora host is missing a security update.
File: fedora_2018-c279b3696f.nasl - Type: ACT_GATHER_INFO
2018-11-26 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-4344.nasl - Type: ACT_GATHER_INFO
2018-04-30 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-4181.nasl - Type: ACT_GATHER_INFO
2018-04-23 Name: The remote Fedora host is missing a security update.
File: fedora_2018-f6dc921a19.nasl - Type: ACT_GATHER_INFO
2018-04-23 Name: The remote Fedora host is missing a security update.
File: fedora_2018-57fbdb1cb5.nasl - Type: ACT_GATHER_INFO
2018-04-16 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_48894ca93e6f11e892f0f0def167eeea.nasl - Type: ACT_GATHER_INFO
2018-01-15 Name: The remote Fedora host is missing a security update.
File: fedora_2017-cbc49efae8.nasl - Type: ACT_GATHER_INFO
2017-11-28 Name: The remote Debian host is missing a security update.
File: debian_DLA-1193.nasl - Type: ACT_GATHER_INFO
2017-11-20 Name: The remote Fedora host is missing a security update.
File: fedora_2017-1560290881.nasl - Type: ACT_GATHER_INFO
2017-11-13 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_f622608cc53c11e7a633009c02a2ab30.nasl - Type: ACT_GATHER_INFO
2017-11-10 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-4030.nasl - Type: ACT_GATHER_INFO
2017-07-17 Name: The remote Fedora host is missing a security update.
File: fedora_2017-7263e7d321.nasl - Type: ACT_GATHER_INFO
2017-07-10 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201707-11.nasl - Type: ACT_GATHER_INFO
2017-06-12 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_bce47c894d3f11e78080a4badb2f4699.nasl - Type: ACT_GATHER_INFO
2017-05-16 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2017-580.nasl - Type: ACT_GATHER_INFO
2017-05-09 Name: The remote Fedora host is missing a security update.
File: fedora_2017-ede53aa845.nasl - Type: ACT_GATHER_INFO
2017-05-09 Name: The remote Fedora host is missing a security update.
File: fedora_2017-c8448d0cad.nasl - Type: ACT_GATHER_INFO
2017-05-08 Name: The remote Debian host is missing a security update.
File: debian_DLA-933.nasl - Type: ACT_GATHER_INFO
2017-03-20 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2017-355.nasl - Type: ACT_GATHER_INFO
2017-03-14 Name: The remote Debian host is missing a security update.
File: debian_DLA-855.nasl - Type: ACT_GATHER_INFO
2016-12-27 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201612-44.nasl - Type: ACT_GATHER_INFO
2016-12-14 Name: The remote Fedora host is missing a security update.
File: fedora_2016-b4896f20b3.nasl - Type: ACT_GATHER_INFO
2016-12-14 Name: The remote Fedora host is missing a security update.
File: fedora_2016-60753c3dcd.nasl - Type: ACT_GATHER_INFO
2016-12-12 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2016-1419.nasl - Type: ACT_GATHER_INFO
2016-12-12 Name: The remote Fedora host is missing a security update.
File: fedora_2016-d361d188d9.nasl - Type: ACT_GATHER_INFO