ZarafaCVEs & Vulnerabilities

12 CVEs affecting Zarafa products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

zarafa 110zarafa collaboration platform 30webapp 4webaccess 2
CVE-2021-28994HIGH

kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP headers.

1 Apr 2021
7.5
CVSS
CVE-2019-7219MEDIUM

Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; however, some former Zarafa Webapp customers use the related Kopano product instead.

11 Apr 2019
6.1
CVSS
CVE-2014-5450MEDIUM

Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive information by reading license files.

20 Mar 2018
5.5
CVSS
CVE-2015-6566HIGH

zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.

11 Jan 2016
8.4
CVSS
CVE-2015-3436MEDIUM

provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock.

9 Jun 2015
6.6
CVSS
CVE-2014-9465MEDIUM

senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.2.0 beta 1 allows remote attackers to cause a denial of service (/tmp disk consumption) by uploading a large number of files.

19 Feb 2015
5.0
CVSS
CVE-2014-5449LOW

Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.

20 Oct 2014
2.1
CVSS
CVE-2014-5448LOW

Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by reading the log files.

20 Oct 2014
2.1
CVSS
CVE-2014-5447LOW

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

20 Oct 2014
2.1
CVSS
CVE-2014-0103LOW

WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

29 Jul 2014
2.1
CVSS
CVE-2014-0079MEDIUM

The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the password."

28 Apr 2014
5.0
CVSS
CVE-2014-0037MEDIUM

The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the username."

28 Apr 2014
5.0
CVSS
← PrevPage 1 / 1Next →
Zarafa CVEs & Vulnerabilities — 12 Tracked