Synacor
synacor
94 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (94)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 May 29, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients. |
1Synacor 1Zimbra Collaboration Suite Jun 17, 2026 Apr 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component. |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 Oct 3, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value. |
2Synacor Zimbra2Zimbra Collaboration Suite Zimbra Collaboration SuiteNov 21, 2024 May 30, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group. |
2Synacor Zimbra2Zimbra Collaboration Suite Zimbra Collaboration SuiteNov 21, 2024 May 30, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hija...Show more |
1Synacor 1Zimbra Collaboration Suite Aug 15, 2025 May 10, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Ad...Show more |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 May 10, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through Verbose Error Messages containing a stack dump, tracing data, or full us...Show more |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 May 10, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authen...Show more |
1Synacor 1Zimbra Collaboration Suite Aug 13, 2026 Mar 27, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary...Show more |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 Feb 4, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS. |
1Synacor 1Zimbra Collaboration Suite Nov 21, 2024 Feb 4, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS. |
1Synacor 1Zimbra Collaboration Suite May 13, 2026 May 23, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
1Synacor 1Zimbra Collaboration Suite May 13, 2026 May 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors. |
1Synacor 1Zimbra Collaboration Suite May 13, 2026 May 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations. |
1Synacor 1Zimbra Collaboration Suite May 13, 2026 May 17, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add...Show more |
1Synacor 1Zimbra Collaboration Suite May 13, 2026 Mar 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks. |
1Synacor 1Zimbra Collaboration Suite May 13, 2026 Jan 18, 2017 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect integrity via unknown vectors, aka bug 104477. |
1Synacor 1Zimbra Collaboration Suite May 13, 2026 Jan 18, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104552 and 104703. |
1Synacor 1Zimbra Collaboration Suite May 13, 2026 Jan 18, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276. |
1Synacor 1Zimbra Collaboration Suite May 13, 2026 Jan 18, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Zimbra Collaboration before 8.6.0 Patch 7 allows remote authenticated users to affect availability via unknown vectors, aka bug 102029. |