Lucene search

K
cve[email protected]CVE-2013-5035
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-5035

2022-10-0316:14:55
CWE-362
web.nvd.nist.gov
23
race conditions
htmlcleaner
open-xchange appsuite
email security
thread safety
nvd
cve-2013-5035

4.9 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.6%

Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations.

Affected configurations

NVD
Node
htmlcleaner_projecthtmlcleanerRange2.5
OR
htmlcleaner_projecthtmlcleanerMatch0.8
OR
htmlcleaner_projecthtmlcleanerMatch0.9
OR
htmlcleaner_projecthtmlcleanerMatch1.0
OR
htmlcleaner_projecthtmlcleanerMatch1.0.5
OR
htmlcleaner_projecthtmlcleanerMatch1.1
OR
htmlcleaner_projecthtmlcleanerMatch1.2
OR
htmlcleaner_projecthtmlcleanerMatch1.3
OR
htmlcleaner_projecthtmlcleanerMatch1.4
OR
htmlcleaner_projecthtmlcleanerMatch1.5
OR
htmlcleaner_projecthtmlcleanerMatch1.6
OR
htmlcleaner_projecthtmlcleanerMatch1.12
OR
htmlcleaner_projecthtmlcleanerMatch1.13
OR
htmlcleaner_projecthtmlcleanerMatch1.55
OR
htmlcleaner_projecthtmlcleanerMatch2.0
OR
htmlcleaner_projecthtmlcleanerMatch2.1
OR
htmlcleaner_projecthtmlcleanerMatch2.2
OR
htmlcleaner_projecthtmlcleanerMatch2.2.1
OR
htmlcleaner_projecthtmlcleanerMatch2.4
AND
open-xchangeopen-xchange_appsuiteMatch7.2.2

4.9 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.6%