Vulnerabilities > Roundcube > Webmail > 1.0.11

DATE CVE VULNERABILITY TITLE RISK
2017-01-30 CVE-2015-2181 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Roundcube Webmail
Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.
network
low complexity
roundcube CWE-119
6.5
2016-12-08 CVE-2016-9920 Improper Access Control vulnerability in Roundcube Webmail
steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.
network
roundcube CWE-284
6.0
2016-08-25 CVE-2016-4069 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.
6.8