Vulnerabilities (CVE)

Filtered by vendor Zimbra Subscribe
Filtered by product Collaboration
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41106 1 Zimbra 1 Collaboration 2023-12-12 N/A 7.5 HIGH
An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An attacker can gain access to a Zimbra account. This is also fixed in 9.0.0 Patch 35 and 8.8.15 Patch 42.
CVE-2022-27925 1 Zimbra 1 Collaboration 2023-08-08 6.5 MEDIUM 7.2 HIGH
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
CVE-2022-27924 1 Zimbra 1 Collaboration 2022-05-03 5.0 MEDIUM 7.5 HIGH
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.