Vulnerabilities > Kolab > Kolab Groupware Server

DATE CVE VULNERABILITY TITLE RISK
2008-09-22 CVE-2008-4165 Cryptographic Issues vulnerability in Kolab Groupware Server 1.0.0
admin/user/create_user.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows local administrators, and possibly remote attackers, to obtain cleartext passwords by reading the ssl_access_log file or the referer string.
network
low complexity
kolab CWE-310
4.0
2006-01-14 CVE-2006-0213 Local Security vulnerability in Kolab Groupware Server 2.0.1/2.0.2
Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.
local
low complexity
kolab
4.6
2005-12-31 CVE-2005-4828 Remote Security vulnerability in Kolab Groupware Server 2.0.0/2.0.1
Kolab Server 2.0.0 and 2.0.1 does not properly handle when a large email is sent with a "." in the wrong place, which causes kolabfilter to add another ".", which might break clear-text signatures and attachments.
network
low complexity
kolab
6.4
2004-05-05 CVE-2004-1997 Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges.
local
low complexity
kolab openpkg
4.6