All CVEs — page 66 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw is a use-after-free vulnerability in QEMU's 9pfs subsystem, allowing a malicious guest user to escape the shared directory boundary and perform arbitrary file read/write and code execution.
A cross-site scripting (XSS) vulnerability allows unauthenticated attackers to inject malicious content into a COUNTER message's RFC From address, leading to potential access to victim's mailbox data.
This flaw allows unauthenticated attackers to perform path-traversal writes and execute commands as zimbra by abusing unsigned save fields in supported public Briefcase documents.
This vulnerability allows unauthenticated attackers to forge a share notification, leading to stored Cross-Site Scripting (XSS) and potential access to the victim's mailbox data.
This flaw allows unauthenticated attackers to forge a share notification, leading to stored cross-site scripting (XSS) when a signed-in user clicks on it, granting the attacker access to the victim's mailbox data.
The vulnerability allows an authenticated attacker to inject arbitrary commands via a crafted GIM bundle, leading to potential arbitrary command execution with elevated privileges.