Horde Vulnerabilities

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

Horde Groupware Webmail Edition24
Horde Groupware20
Horde IMP18
Horde Application Framework16
Horde Kronolith6

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Remediation

Official Fix96
Temporary Fix0
Workaround0
Unavailable2
Not Defined18

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploitability

High8
Functional0
Proof-of-Concept32
Unproven4
Not Defined72

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Access Vector

Not Defined0
Physical0
Local2
Adjacent0
Network114

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Authentication

Not Defined0
High0
Low28
None88

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

User Interaction

Not Defined0
Required84
None32

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

C3BM Index

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

CVSSv3 Base

≤10
≤20
≤30
≤46
≤546
≤618
≤724
≤818
≤92
≤102

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

CVSSv3 Temp

≤10
≤20
≤30
≤414
≤546
≤630
≤714
≤88
≤92
≤102

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

VulDB

≤10
≤20
≤30
≤48
≤550
≤614
≤728
≤812
≤92
≤102

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

NVD

≤10
≤20
≤30
≤40
≤50
≤60
≤712
≤80
≤98
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

CNA

≤10
≤20
≤30
≤40
≤50
≤60
≤72
≤80
≤90
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Research

≤10
≤20
≤30
≤40
≤50
≤60
≤70
≤80
≤90
≤100

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploit 0-day

<1k24
<2k70
<5k18
<10k2
<25k2
<50k0
<100k0
≥100k0

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploit Today

<1k116
<2k0
<5k0
<10k0
<25k0
<50k0
<100k0
≥100k0

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Exploit Market Volume

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

🔴 CTI Activities

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Affected Products (28): Accounts (1), Application Framework (16), Chora (1), Forwards (1), Gollem (1), Groupware (18), Groupware Webmail Edition (19), Horde Application Framework (1), IMP (24), IMP Webmail (7), IMP Webmail Client (1), Ingo H3 (1), Kronolith (6), Kronolith H3 (3), Kronolith H4 (1), Manager (1), Mnemo (1), Nag (1), Nag Task List Manager H3 (1), Passwd (1), Turba (1), Turba Contact Manager (1), Turba Contact Manager H3 (1), Turba H3 (2), Vaction (1), Webmail (3), cPanel (1), passwd (1)

Link to Vendor Website: https://www.horde.org/

PublishedBaseTempVulnerabilityProdExpRemEPSSCTICVE
06/09/20226.36.3Horde Webmail Address Book Driver.php create injectionGroupware SoftwareNot DefinedNot Defined0.006750.04CVE-2022-30287
02/14/20214.84.6Horde Groupware Webmail Edition Text Filter Library Text2html.php preProcess cross site scriptingGroupware SoftwareNot DefinedOfficial Fix0.021660.00CVE-2021-26929
05/18/20205.24.6Horde Groupware Webmail Edition Image View Stored cross site scriptingGroupware SoftwareNot DefinedOfficial Fix0.001350.04CVE-2020-8035
03/23/20205.05.0Horde Groupware Webmail Edition add.php unrestricted uploadGroupware SoftwareNot DefinedNot Defined0.004670.08CVE-2020-8866
03/23/20206.36.3Horde Groupware Webmail Edition edit.php path traversalGroupware SoftwareNot DefinedNot Defined0.003330.17CVE-2020-8865
02/17/20208.58.5Horde Groupware Webmail Edition CSV Data code injectionGroupware SoftwareNot DefinedNot Defined0.964920.05CVE-2020-8518
11/05/20195.45.1Horde Groupware Webmail Edition basic.php cross-site request forgeryGroupware SoftwareProof-of-ConceptOfficial Fix0.032800.02CVE-2013-6275
11/05/20194.84.3Horde Groupware Webmail Edition Permission edit.php cross-site request forgeryGroupware SoftwareProof-of-ConceptNot Defined0.001970.00CVE-2013-6365
11/05/20196.55.9Horde Groupware Webmail Edition Virtual Address Book search.php cross-site request forgeryGroupware SoftwareProof-of-ConceptNot Defined0.004590.00CVE-2013-6364
10/24/20196.56.5Horde Groupware Webmail Edition Trean cross-site request forgeryGroupware SoftwareProof-of-ConceptNot Defined0.049100.00CVE-2019-12095
10/24/20195.25.2Horde Groupware Webmail Edition Tag Cloud cross site scriptingGroupware SoftwareProof-of-ConceptNot Defined0.007530.02CVE-2019-12094
05/29/20197.57.5Horde Groupware Webmail Edition Image Upload Type.php onSubmit code injectionGroupware SoftwareNot DefinedNot Defined0.944910.02CVE-2019-9858
04/04/20176.96.7Horde Groupware Webmail Edition Horde_Crypt command injectionGroupware SoftwareNot DefinedOfficial Fix0.001810.00CVE-2017-7414
04/04/20177.57.4Horde Groupware Webmail Edition Horde_Crypt command injectionGroupware SoftwareNot DefinedOfficial Fix0.947730.03CVE-2017-7413
04/13/20166.15.9Horde Groupware Webmail Edition _menubar.html.php cross site scriptingGroupware SoftwareNot DefinedOfficial Fix0.005340.00CVE-2016-2228
04/13/20166.15.9Horde Groupware Webmail Edition Html.php _renderVarInput_number cross site scriptingGroupware SoftwareNot DefinedOfficial Fix0.004340.00CVE-2015-8807
11/19/20154.33.9Horde Groupware cmdshell.php cross-site request forgeryGroupware SoftwareProof-of-ConceptOfficial Fix0.007290.00CVE-2015-7984
11/18/20155.44.7Horde Groupware cmdshell.php cross-site request forgeryGroupware SoftwareProof-of-ConceptOfficial Fix0.007290.00CVE-2015-7984
07/07/20144.34.1Horde IMP Flag/Mailbox cross site scriptingGroupware SoftwareHighOfficial Fix0.002400.02CVE-2014-4946
07/07/20144.34.1Horde IMP Mailbox/Message View cross site scriptingGroupware SoftwareHighOfficial Fix0.002390.00CVE-2014-4945
06/03/20147.36.4Horde Webmail Horde_ldap improper authenticationGroupware SoftwareUnprovenOfficial Fix0.008290.00CVE-2014-3999
04/05/20144.34.1Horde Groupware cross site scriptingGroupware SoftwareNot DefinedOfficial Fix0.001460.02CVE-2012-6640
04/05/20144.34.1Horde Groupware Portal Blocks cross site scriptingGroupware SoftwareNot DefinedOfficial Fix0.003160.00CVE-2012-5567
04/05/20144.34.1Horde Groupware cross site scriptingGroupware SoftwareNot DefinedOfficial Fix0.002540.00CVE-2012-5565
03/31/20145.34.7Horde Webmail Redirect go.php privileges managementGroupware SoftwareProof-of-ConceptUnavailable0.000000.02

91 more entries are not shown

Want to stay up to date on a daily basis?

Enable the mail alert feature now!