CVEs (85)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Roundcube2Fedora WebmailJun 17, 2026 Aug 20, 2019 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks. |
3Fedoraproject OpensuseRoundcube4Backports Sle FedoraLeap+1 moreJun 17, 2026 Apr 7, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or A...Show more |
2Debian Roundcube2Debian Linux WebmailNov 21, 2024 Nov 12, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment. |
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/li...Show more |
11Apple BloopEmclient+8 more11Airmail EmclientHorde Imp+8 moreNov 21, 2024 May 16, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications th...Show more |
2Debian Roundcube2Debian Linux WebmailJun 17, 2026 Apr 7, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plug...Show more |
roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity. |
2Debian Roundcube2Debian Linux WebmailApr 21, 2026 Nov 9, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017...Show more |
1Roundcube 2Roundcube Webmail WebmailMay 13, 2026 May 23, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory. |
1Roundcube 2Roundcube Webmail WebmailMay 13, 2026 May 23, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard. |
1Roundcube 2Roundcube Webmail WebmailMay 13, 2026 May 23, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI. |
Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in t...Show more |
2Opensuse Roundcube4Leap OpensuseRoundcube Webmail+1 moreMay 13, 2026 Apr 13, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-...Show more |
2Opensuse Roundcube4Leap OpensuseRoundcube Webmail+1 moreMay 13, 2026 Apr 13, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-...Show more |
rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element. |
Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username. |
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password. |
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the href attribute in an area tag in an e-mail message. |
steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the...Show more |
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk c...Show more |