2 results (0.003 seconds)

CVSS: 9.8EPSS: 0%CPEs: 18EXPL: 0

27 Apr 2010 — Unspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server before 2.2.3 allows attackers to have an unspecified impact via vectors related to an "image upload form." Vulnerabilidad no especificada en Kolab Webclient anterior v1.2.0 en Kolab Server anterior v2.2.3 permite a atacantes remotos tener un impacto no especificado a través de vectores relacionados con un "formulario de carga de imagen" • http://files.kolab.org/server/release/kolab-server-2.2.3/sources/release-notes.txt •

CVSS: 5.5EPSS: 2%CPEs: 8EXPL: 0

23 Aug 2007 — ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information. ClamAV anterior a 0.91.2, us... • http://docs.info.apple.com/article.html?artnum=307562 •