// For flags

CVE-2013-5035

 

Severity Score

5.3
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations.

Múltiples vulnerabilidades de condición de carrera en HtmlCleaner anterior a v2.6, como es utilizado en Open-Xchange AppSuite v7.2.2 anterior a rev13 y otros productos, permiten a los usuarios remotos autenticados leer el correo electrónico privado de otras personas en situaciones oportunistas, mediante el aprovechamiento de la falta de seguridad de los subprocesos y la realización de una serie rápida de (1) envío de emails o (2) operaciones de guardado de borradores.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-08-02 CVE Reserved
  • 2013-08-16 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 First Exploit
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
<= 2.5
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version " <= 2.5"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
0.8
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "0.8"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
0.9
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "0.9"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
1.0
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "1.0"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
1.0.5
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "1.0.5"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
1.1
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "1.1"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
1.2
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "1.2"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
1.3
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "1.3"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
1.4
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "1.4"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
1.5
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "1.5"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
1.6
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "1.6"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
1.12
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "1.12"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
1.13
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "1.13"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
1.55
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "1.55"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
2.0
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "2.0"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
2.1
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "2.1"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
2.2
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "2.2"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
2.2.1
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "2.2.1"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected
Htmlcleaner Project
Search vendor "Htmlcleaner Project"
Htmlcleaner
Search vendor "Htmlcleaner Project" for product "Htmlcleaner"
2.4
Search vendor "Htmlcleaner Project" for product "Htmlcleaner" and version "2.4"
-
Affected
in Open-xchange
Search vendor "Open-xchange"
Open-xchange Appsuite
Search vendor "Open-xchange" for product "Open-xchange Appsuite"
7.2.2
Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2"
-
Affected