Количество 75 967
Количество 75 967
CVE-2026-7511
PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.
CVE-2026-75032
(A flaw was found in BlueZ. Insufficient validation of packet length fi ...)
CVE-2026-75010
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
CVE-2026-75007
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.
CVE-2026-75006
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
CVE-2026-75004
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
CVE-2026-75003
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.
CVE-2026-75002
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
CVE-2026-75000
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
CVE-2026-74999
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
CVE-2026-74998
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
CVE-2026-74997
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
CVE-2026-74990
(Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
CVE-2026-74989
(Internally found bugs present in Thunderbird 153. Some of these bugs s ...)
CVE-2026-74988
(Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird ...)
CVE-2026-74987
(Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
CVE-2026-74986
(Site isolation issue in the CSS Parsing and Computation component. Thi ...)
CVE-2026-74985
(Privilege escalation in the Enterprise Policies component. This vulner ...)
CVE-2026-74984
(Race condition in the JavaScript Engine component. This vulnerability ...)
CVE-2026-74983
(Mitigation bypass in the Data Loss Prevention component. This vulnerab ...)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-7511 PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-75032 (A flaw was found in BlueZ. Insufficient validation of packet length fi ...) | CVSS3: 6.3 | 0% Низкий | 9 дней назад | |
CVE-2026-75010 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver. | CVSS3: 6.4 | 0% Низкий | 10 дней назад | |
CVE-2026-75007 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation. | CVSS3: 5.4 | 0% Низкий | 10 дней назад | |
CVE-2026-75006 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643. | CVSS3: 5.8 | 0% Низкий | 10 дней назад | |
CVE-2026-75004 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin. | CVSS3: 4.3 | 0% Низкий | 10 дней назад | |
CVE-2026-75003 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation. | CVSS3: 5.8 | 0% Низкий | 10 дней назад | |
CVE-2026-75002 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection. | CVSS3: 7.1 | 1% Низкий | 10 дней назад | |
CVE-2026-75000 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation. | CVSS3: 5.8 | 0% Низкий | 10 дней назад | |
CVE-2026-74999 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. | CVSS3: 5.4 | 0% Низкий | 10 дней назад | |
CVE-2026-74998 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing. | CVSS3: 7.2 | 0% Низкий | 10 дней назад | |
CVE-2026-74997 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver. | CVSS3: 8.8 | 1% Низкий | 10 дней назад | |
CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...) | CVSS3: 9.8 | 1% Низкий | 9 дней назад | |
CVE-2026-74989 (Internally found bugs present in Thunderbird 153. Some of these bugs s ...) | CVSS3: 9.8 | 0% Низкий | 9 дней назад | |
CVE-2026-74988 (Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird ...) | CVSS3: 9.8 | 0% Низкий | 9 дней назад | |
CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...) | CVSS3: 9.8 | 1% Низкий | 9 дней назад | |
CVE-2026-74986 (Site isolation issue in the CSS Parsing and Computation component. Thi ...) | CVSS3: 9.1 | 0% Низкий | 9 дней назад | |
CVE-2026-74985 (Privilege escalation in the Enterprise Policies component. This vulner ...) | CVSS3: 9.8 | 0% Низкий | 9 дней назад | |
CVE-2026-74984 (Race condition in the JavaScript Engine component. This vulnerability ...) | CVSS3: 6.8 | 0% Низкий | 9 дней назад | |
CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This vulnerab ...) | CVSS3: 8.1 | 0% Низкий | 9 дней назад |
Уязвимостей на страницу