CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
65066 | CVE-2013-5119 | Candidate | Zimbra Collaboration Suite (ZCS) 6.0.16 and earlier allows man-in-the-middle attackers to obtain access by sniffing the network and replaying the ZM_AUTH_TOKEN token. | Assigned (20130813) | None (candidate not yet proposed) | View | |
90234 | CVE-2016-3415 | Candidate | Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276. | Assigned (20160317) | None (candidate not yet proposed) | View | |
47312 | CVE-2010-4728 | Candidate | Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protection mechanisms based on randomization by predicting a return value, as demonstrated by the authid protection mechanism. | Assigned (20110208) | None (candidate not yet proposed) | View | |
47313 | CVE-2010-4729 | Candidate | Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote attackers to generate a flood of password requests and possibly conduct cross-site request forgery (CSRF) attacks via multiple form submissions. | Assigned (20110208) | None (candidate not yet proposed) | View | |
51738 | CVE-2011-3826 | Candidate | Zikula 1.2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/voodoodolly/version.php and certain other files. | Assigned (20110923) | None (candidate not yet proposed) | View |
Page 23 of 20943, showing 5 records out of 104715 total, starting on record 111, ending on 115