Search CVE reports


Toggle filters

1 – 4 of 4 results


CVE-2022-26562

Medium priority

Some fixes available 3 of 5

An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor...

1 affected package

kopanocore

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kopanocore Not in release Fixed Fixed Fixed Ignored
Show less packages

CVE-2021-28994

Medium priority
Vulnerable

kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP headers.

1 affected package

kopanocore

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kopanocore Not in release Vulnerable Vulnerable Vulnerable Not in release
Show less packages

CVE-2020-8014

Unknown priority
Not affected

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue...

1 affected package

kopanocore

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kopanocore Not affected Not affected Not in release
Show less packages

CVE-2019-19907

Medium priority

Some fixes available 1 of 3

HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data.

1 affected package

kopanocore

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
kopanocore Not in release Not affected Not affected Fixed Not in release
Show less packages