Логотип exploitDog
bind:CVE-2017-7414
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-7414

Количество 4

Количество 4

ubuntu логотип

CVE-2017-7414

почти 9 лет назад

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled in the user's preferences, and has enabled the "Should PGP signed messages be automatically verified when viewed?" preference. To exploit this vulnerability, an attacker can send a PGP signed email (that is maliciously crafted) to the Horde user, who then must either view or preview it.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-7414

почти 9 лет назад

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled in the user's preferences, and has enabled the "Should PGP signed messages be automatically verified when viewed?" preference. To exploit this vulnerability, an attacker can send a PGP signed email (that is maliciously crafted) to the Horde user, who then must either view or preview it.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-7414

почти 9 лет назад

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Editio ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-66jj-9jf3-x628

больше 3 лет назад

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled in the user's preferences, and has enabled the "Should PGP signed messages be automatically verified when viewed?" preference. To exploit this vulnerability, an attacker can send a PGP signed email (that is maliciously crafted) to the Horde user, who then must either view or preview it.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-7414

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled in the user's preferences, and has enabled the "Should PGP signed messages be automatically verified when viewed?" preference. To exploit this vulnerability, an attacker can send a PGP signed email (that is maliciously crafted) to the Horde user, who then must either view or preview it.

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-7414

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled in the user's preferences, and has enabled the "Should PGP signed messages be automatically verified when viewed?" preference. To exploit this vulnerability, an attacker can send a PGP signed email (that is maliciously crafted) to the Horde user, who then must either view or preview it.

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-7414

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Editio ...

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
github логотип
GHSA-66jj-9jf3-x628

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled in the user's preferences, and has enabled the "Should PGP signed messages be automatically verified when viewed?" preference. To exploit this vulnerability, an attacker can send a PGP signed email (that is maliciously crafted) to the Horde user, who then must either view or preview it.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу