Known vulnerabilities in Zimbra Collaboration 8.8.15 Patch 26 - page 2
Vendor:
Synacor Inc.
Software:
Zimbra Collaboration
Version:
8.8.15 Patch 26
Software CPE:
cpe:2.3:a:synacor:zimbra_collaboration:*:*:*:*:*:*:*:*
Website:
https://www.zimbra.com/
Total vulnerabilities:
57
Public exploits:
10
Known exploited (KEV):
10
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
10.1.20
10.1.19
10.1.18
10.1.17
10.1.16
10.1.15
10.1.14
10.0.18
10.1.13
10.1.12
10.1.11
10.0.17
10.1.10
10.0.16
10.1.9
10.0.15
9.0.0 Patch 46
10.1.8
10.0.14
9.0.0 Patch 45
10.1.7
10.1.6
10.1.5
10.0.13
9.0.0 Patch 44
10.1.4
10.0.12
9.0.0 Patch 43
8.8.15 Patch 47
10.1.3
10.0.11
10.1.2
10.0.10
9.0.0 Patch 42
10.1.1
10.0.9
9.0.0 Patch 41
8.8.15 Patch 46
10.1.0
10.0.8
9.0.0 Patch 40
10.0.7
9.0.0 Patch 39
8.8.15 Patch 45
9.0.0 Patch 38
10.0.6
10.0.5
9.0.0 Patch 37
8.8.15 Patch 44
10.0.4
9.0.0 Patch 36
8.8.15 Patch 43
10.0.3
9.0.0 Patch 35
8.8.15 Patch 42
10.0.2
9.0.0 Patch 34
8.8.15 Patch 41
10.0.1
9.0.0 Patch 33
8.8.15 Patch 40
10.0.0
9.0.0 Patch 32
8.8.15 Patch 39
9.0.0 Patch 31
8.8.15 Patch 38
9.0.0 Patch 30
8.8.15 Patch 37
9.0.0 Patch 29
8.8.15 Patch 36
9.0.0 Patch 28
8.8.15 Patch 35
9.0.0 Patch 27
8.8.15 Patch 34
9.0.0 Patch 26
8.8.15 Patch 33
9.0.0 Patch 25
8.8.15 Patch 32
9.0.0 Patch 24.1
8.8.15 Patch 31.1
9.0.0 Patch 24
8.8.15 Patch 31
9.0.0 Patch 23
9.0.0 Patch 22
9.0.0 Patch 21
9.0.0 Patch 20
9.0.0 Patch 19
9.0.0 Patch 18
8.8.15 Patch 30
8.8.15 Patch 29
8.8.15 Patch 28
8.8.15 Patch 27
8.8.15 Patch 26
8.8.15 Patch 25
9.0.0 Patch 17
8.8.15 Patch 24
9.0.0 Patch 16
8.8.15 Patch 23
9.0.0 Patch 15
8.8.15 Patch 22
9.0.0 Patch 14
8.8.15 Patch 21
9.0.0 Patch 13
9.0.0 Patch 12
9.0.0 Patch 11
9.0.0 Patch 10
9.0.0 Patch 9
9.0.0 Patch 8
9.0.0 Patch 7
9.0.0 Patch 6
9.0.0 Patch 5
9.0.0 Patch 4
9.0.0 Patch 3
9.0.0 Patch 2
9.0.0 Patch 1
8.8.15 Patch 20
8.8.15 Patch 19
8.8.15 Patch 18
8.8.15 Patch 17
8.8.15 Patch 16
8.8.15 Patch 15
8.8.15 Patch 14
8.8.15 Patch 13
8.8.15 Patch 12
8.8.15 Patch 11
8.8.15 Patch 10
8.8.15 Patch 9
8.8.15 Patch 8
8.8.15 Patch 7
8.8.15 Patch 6
8.8.15 Patch 5
8.8.15 Patch 4
8.8.15 Patch 3
8.8.15 Patch 2
9.0.0
8.8.15
8.8.12 Patch 6
8.8.12 Patch 5
8.8.12 Patch 4
8.8.12 Patch 3
8.8.12 Patch 2
8.8.12 Patch 1
8.8.11 Patch 5
8.8.11 Patch 4
8.8.11 Patch 3
8.8.11 Patch 2
8.8.10 Patch 8
8.8.10 Patch 7
8.8.10 Patch 6
8.8.9 Patch 10
8.7.11 Patch 14
8.7.11 Patch 13
8.7.11 Patch 12
8.7.11 Patch 11
8.7.11 Patch 10
8.7.11 Patch 9
8.7.11 Patch 8
8.6.0 Patch 14
8.6.0 Patch 13
8.8.15 Patch 1
8.8.12
8.8.11 Patch 1
8.8.10 Patch 5
8.8.10 Patch 4
8.8.10 Patch 3
8.8.10 Patch 2
8.8.10 Patch 1
8.8.9 Patch 9
8.8.9 Patch 8
8.8.9 Patch 7
8.8.9 Patch 6
8.8.9 Patch 5
8.8.9 Patch 4
8.8.9 Patch 3
8.8.9 Patch 2
8.8.9 Patch 1
8.8.8 Patch 10
8.8.8 Patch 9
8.8.8 Patch 8
8.8.8 Patch 7
8.8.8 Patch 6
8.8.8 Patch 5
8.8.8 Patch 4
8.8.8 Patch 3
8.8.8 Patch 2
8.8.8 Patch 1
8.7.11 Patch 7
8.7.11 Patch 6
8.7.11 Patch 5
8.7.11 Patch 4
8.7.11 Patch 3
8.7.11 Patch 2
8.6.0 Patch 12
8.6.0 Patch 11
8.6.0 Patch 10
8.8.11
8.8.10
8.8.9
8.8
8.8.8
8.8.7
8.8.6
8.8.0
8.7.11 Patch 1
8.7.11
8.7.10
8.7.9
8.7.8
8.7.7
8.7.6
8.7.5
8.7.4
8.7.3
8.7.2
8.7.1
8.7.0
8.6.0 Patch 9
8.6.0 Patch 8
8.6.0 Patch 7
8.6.0 Patch 6
8.6.0 Patch 5
8.6.0 Patch 4
8.6.0 Patch 3
8.6.0 Patch 2
8.6.0 Patch 1
8.6.0
8.5.1
8.5.0 Patch 2
8.5.0 Patch 1
8.5.0
8.0.7 Patch 2
8.0.7 Patch 1
8.0.5 Patch 1
8.0.4 Patch 2
8.0.4 Patch 1
8.0.3 Patch 3
8.0.3 Patch 2
8.0.3 Patch 1
8.0.2 Patch 1
8.0.9
8.0.8
8.0.7
8.0.6
8.0.5
8.0.4
8.0.3
8.0.2
8.0.1
8.0.0
7.2.7
Vulnerabilities (57)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU79877 - Improper Authentication CVE-2023-41106 |
CWE-287 | Medium | 8.8.15 Patch 42, 9.0.0 Patch 35, 10.0.3 | 23.08.2023 |
SB2023082306 |
||
| #VU78672 - Exposure of sensitive information to an unauthorized actor CVE-2023-38750 |
CWE-200 | Medium | 8.8.15 Patch 41, 9.0.0 Patch 34, 10.0.2 | 26.07.2023 |
SB2023072608 |
||
| #VU78242 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-37580 |
CWE-79 | High | 8.8.15 Patch 41 | 13.07.2023 |
SB2023071343 |
||
| #VU76649 - Improper Authentication CVE-2023-29381 |
CWE-287 | Medium | 8.8.15 Patch 40, 9.0.0 Patch 33, 10.0.1 | 30.05.2023 |
SB2023053035 |
||
| #VU76648 - Improper Authentication CVE-2023-29382 |
CWE-287 | High | 8.8.15 Patch 40, 9.0.0 Patch 33, 10.0.1 | 30.05.2023 |
SB2023053035 |
||
| #VU76646 - Security Features CVE-2023-34193 |
CWE-254 | Medium | 8.8.15 Patch 40, 9.0.0 Patch 33, 10.0.1 | 30.05.2023 |
SB2023053035 |
||
| #VU76645 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-34192 |
CWE-79 | Medium | 8.8.15 Patch 40 | 30.05.2023 |
SB2023053035 |
||
| #VU73960 - Resource exhaustion CVE-2023-0464 |
CWE-400 | Medium | 8.8.15 Patch 41, 9.0.0 Patch 34, 10.0.2 | 22.03.2023 |
SB2023032241 SB2023033057 SB2023033058 and 100 more |
||
| #VU73107 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2023-25690 |
CWE-113 | Medium | 8.8.15 Patch 40, 9.0.0 Patch 33, 10.0.1 | 07.03.2023 |
SB2023030731 SB2023030862 SB2023030942 and 54 more |
||
| #VU72474 - Improper Authorization |
CWE-285 | Low | 8.8.15 Patch 37, 9.0.0 Patch 30 | 21.02.2023 |
SB2023022183 |
||
| #VU71993 - Information Exposure Through Timing Discrepancy CVE-2022-4304 |
CWE-208 | Medium | 8.8.15 Patch 37, 9.0.0 Patch 30 | 07.02.2023 |
SB2023020742 SB2023020748 SB2023020767 and 222 more |
||
| #VU71992 - Type confusion CVE-2023-0286 |
CWE-843 | High | 8.8.15 Patch 37, 9.0.0 Patch 30 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 223 more |
||
| #VU70444 - Server-Side Request Forgery (SSRF) CVE-2022-46364 |
CWE-918 | Medium | 8.8.15 Patch 40, 9.0.0 Patch 33, 10.0.1 | 20.12.2022 |
SB2022122009 SB2023011329 SB2023011707 and 67 more |
||
| #VU69502 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Medium | 8.8.15 Patch 35, 9.0.0 Patch 28 | 22.11.2022 |
SB2022112233 |
||
| #VU69501 - Unrestricted Upload of File with Dangerous Type |
CWE-434 | Medium | 8.8.15 Patch 35, 9.0.0 Patch 28 | 22.11.2022 |
SB2022112233 |
||
| #VU64078 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-26377 |
CWE-444 | Medium | 8.8.15 Patch 35, 9.0.0 Patch 28 | 08.06.2022 |
SB2022060817 SB2022060901 SB2022061611 and 39 more |
||
| #VU63084 - Improper input validation CVE-2022-22970 |
CWE-20 | Medium | 8.8.15 Patch 40, 9.0.0 Patch 33, 10.0.1 | 12.05.2022 |
SB2022051201 SB2022060620 SB2022062223 and 23 more |
||
| #VU62802 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-20771 |
CWE-835 | Medium | 8.8.15 Patch 35, 9.0.0 Patch 28 | 04.05.2022 |
SB2022050437 SB2022051732 SB2022051836 and 14 more |
||
| #VU62800 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-20770 |
CWE-835 | Medium | 8.8.15 Patch 35, 9.0.0 Patch 28 | 04.05.2022 |
SB2022050437 SB2022051732 SB2022051836 and 14 more |
||
| #VU61671 - Memory corruption CVE-2018-25032 |
CWE-119 | Medium | 8.8.15 Patch 37, 9.0.0 Patch 30 | 28.03.2022 |
SB2022032844 SB2022032845 SB2022033018 and 192 more |
Showing elements 21 - 40 out of 57