
CVE-2009-4824
https://notcve.org/view.php?id=CVE-2009-4824
27 Apr 2010 — Unspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server before 2.2.3 allows attackers to have an unspecified impact via vectors related to an "image upload form." Vulnerabilidad no especificada en Kolab Webclient anterior v1.2.0 en Kolab Server anterior v2.2.3 permite a atacantes remotos tener un impacto no especificado a través de vectores relacionados con un "formulario de carga de imagen" • http://files.kolab.org/server/release/kolab-server-2.2.3/sources/release-notes.txt •

CVE-2007-4510
https://notcve.org/view.php?id=CVE-2007-4510
23 Aug 2007 — ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information. ClamAV anterior a 0.91.2, us... • http://docs.info.apple.com/article.html?artnum=307562 •

CVE-2004-1997
https://notcve.org/view.php?id=CVE-2004-1997
05 May 2004 — Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges. • http://marc.info/?l=bugtraq&m=108377525924422&w=2 •