<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:05:29 +0000</lastBuildDate>
    <item>
      <title>CVE-2016-4069</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2016-4069</link>
      <description>&lt;p&gt;Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2016-4069</guid>
    </item>
    <item>
      <title>USN-8132-1 — roundcube vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8132-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: roundcube, Ubuntu:Pro:18.04:LTS: roundcube&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly sanitize 
certain HTML elements within the e-mail body. An attacker could possibly 
use this issue to cause a cross-site scripting attack. This issue was only 
addressed in Ubuntu 16.04 LTS. (CVE-2016-4068, CVE-2016-4069)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly handle certain 
configuration parameters. An attacker could possibly use this issue to 
execute arbitrary code. This issue was only addressed in Ubuntu 16.04 LTS. 
(CVE-2016-9920)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly sanitize CSS styles 
within SVG documents. An attacker could possibly use this issue to cause 
a cross-site scripting attack. This issue was only addressed in Ubuntu 16.04 LTS.
(CVE-2017-6820)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly restrict exec call in 
certain drivers of the password plugin. An authenticated user could possibly 
use this issue to perform arbitrary password resets. This issue was only addressed in 
Ubuntu 16.04 LTS. (CVE-2017-8114)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly set file permissions within 
the Enigma plugin. An attacker could possibly use this issue to exfiltrate GPG private 
keys via network connectivity. (CVE-2018-1000071)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly handle GnuPG MDC 
integrity-protection warnings. An attacker could possibly use this issue to obtain 
sensitive information from encrypted communications. (CVE-20…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: roundcube, Ubuntu:Pro:18.04:LTS: roundcube&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly sanitize 
certain HTML elements within the e-mail body. An attacker could possibly 
use this issue to cause a cross-site scripting attack. This issue was only 
addressed in Ubuntu 16.04 LTS. (CVE-2016-4068, CVE-2016-4069)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly handle certain 
configuration parameters. An attacker could possibly use this issue to 
execute arbitrary code. This issue was only addressed in Ubuntu 16.04 LTS. 
(CVE-2016-9920)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly sanitize CSS styles 
within SVG documents. An attacker could possibly use this issue to cause 
a cross-site scripting attack. This issue was only addressed in Ubuntu 16.04 LTS.
(CVE-2017-6820)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly restrict exec call in 
certain drivers of the password plugin. An authenticated user could possibly 
use this issue to perform arbitrary password resets. This issue was only addressed in 
Ubuntu 16.04 LTS. (CVE-2017-8114)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly set file permissions within 
the Enigma plugin. An attacker could possibly use this issue to exfiltrate GPG private 
keys via network connectivity. (CVE-2018-1000071)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly handle GnuPG MDC 
integrity-protection warnings. An attacker could possibly use this issue to obtain 
sensitive information from encrypted communications. (CVE-20…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8132-1</guid>
    </item>
  </channel>
</rss>
