Horde / Horde Application Framework
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2015-7984 | Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2… | MEDIUM | 6.8 | Nov 19, 2015 |
| CVE-2014-1691 | The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and exe… | HIGH | 7.5 | Apr 1, 2014 |
| CVE-2010-3694 | Cross-site request forgery (CSRF) vulnerability in the Horde Application Framework before 3.3.9 allows remote attackers to hijack the authentication of unspeci… | MEDIUM | 6.8 | Nov 9, 2010 |
| CVE-2010-3077 | Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary w… | MEDIUM | 4.3 | Nov 9, 2010 |
| CVE-2009-3237 | Horde: XSS in "number" type preferences and in MIME rendering | MEDIUM | 4.3 | Sep 17, 2009 |
| CVE-2007-1474 | Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delet… | MEDIUM | 6.8 | Mar 16, 2007 |
| CVE-2007-1473 | Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selection box, a… | MEDIUM | 4.3 | Mar 16, 2007 |
| CVE-2006-3549 | services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows… | MEDIUM | 5.0 | Jul 13, 2006 |
| CVE-2005-4190 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script… | LOW | 3.5 | Dec 13, 2005 |
Showing 1 to 9 of 9 CVEs