Lucene search

K
nvd[email protected]NVD:CVE-2010-0464
HistoryJan 29, 2010 - 6:30 p.m.

CVE-2010-0464

2010-01-2918:30:01
CWE-200
web.nvd.nist.gov
2

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.004

Percentile

74.5%

Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.

Affected configurations

Nvd
Node
roundcubewebmailRange0.3.1
OR
roundcubewebmailMatch0.1
OR
roundcubewebmailMatch0.120050811
OR
roundcubewebmailMatch0.120050820
OR
roundcubewebmailMatch0.120051007
OR
roundcubewebmailMatch0.120051021
OR
roundcubewebmailMatch0.1alpha
OR
roundcubewebmailMatch0.1beta
OR
roundcubewebmailMatch0.1beta2
OR
roundcubewebmailMatch0.1rc1
OR
roundcubewebmailMatch0.1rc2
OR
roundcubewebmailMatch0.1stable
OR
roundcubewebmailMatch0.1.1
OR
roundcubewebmailMatch0.2
OR
roundcubewebmailMatch0.2alpha
OR
roundcubewebmailMatch0.2beta
OR
roundcubewebmailMatch0.2stable
OR
roundcubewebmailMatch0.2.1
OR
roundcubewebmailMatch0.2.2
OR
roundcubewebmailMatch0.3
OR
roundcubewebmailMatch0.3beta
OR
roundcubewebmailMatch0.3rc1
OR
roundcubewebmailMatch0.3stable
VendorProductVersionCPE
roundcubewebmail*cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
roundcubewebmail0.1cpe:2.3:a:roundcube:webmail:0.1:*:*:*:*:*:*:*
roundcubewebmail0.1cpe:2.3:a:roundcube:webmail:0.1:20050811:*:*:*:*:*:*
roundcubewebmail0.1cpe:2.3:a:roundcube:webmail:0.1:20050820:*:*:*:*:*:*
roundcubewebmail0.1cpe:2.3:a:roundcube:webmail:0.1:20051007:*:*:*:*:*:*
roundcubewebmail0.1cpe:2.3:a:roundcube:webmail:0.1:20051021:*:*:*:*:*:*
roundcubewebmail0.1cpe:2.3:a:roundcube:webmail:0.1:alpha:*:*:*:*:*:*
roundcubewebmail0.1cpe:2.3:a:roundcube:webmail:0.1:beta:*:*:*:*:*:*
roundcubewebmail0.1cpe:2.3:a:roundcube:webmail:0.1:beta2:*:*:*:*:*:*
roundcubewebmail0.1cpe:2.3:a:roundcube:webmail:0.1:rc1:*:*:*:*:*:*
Rows per page:
1-10 of 231

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.004

Percentile

74.5%