Lucene search

K

Kopano Security Vulnerabilities

cve
cve

CVE-2022-26562

An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Platform (ZCP) in provider/libserver/ECPamAuth.cpp of Zarafa ...

9.8CVSS

9.4AI Score

0.018EPSS

2022-04-01 08:15 PM
63
cve
cve

CVE-2019-19907

HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal...

9.8CVSS

9.3AI Score

0.004EPSS

2019-12-19 06:15 PM
52
cve
cve

CVE-2017-11666

Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a specially crafted previewable...

6.1CVSS

6AI Score

0.001EPSS

2022-10-03 04:23 PM
28
cve
cve

CVE-2021-28994

kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP...

7.5CVSS

7.5AI Score

0.001EPSS

2021-03-31 11:15 PM
35
4