<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:37:23 +0000</lastBuildDate>
    <item>
      <title>CVE-2016-9920</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2016-9920</link>
      <description>&lt;p&gt;steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2016-9920</guid>
    </item>
    <item>
      <title>USN-8132-1 — roundcube vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8132-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: roundcube, Ubuntu:Pro:18.04:LTS: roundcube&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly sanitize 
certain HTML elements within the e-mail body. An attacker could possibly 
use this issue to cause a cross-site scripting attack. This issue was only 
addressed in Ubuntu 16.04 LTS. (CVE-2016-4068, CVE-2016-4069)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly handle certain 
configuration parameters. An attacker could possibly use this issue to 
execute arbitrary code. This issue was only addressed in Ubuntu 16.04 LTS. 
(CVE-2016-9920)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly sanitize CSS styles 
within SVG documents. An attacker could possibly use this issue to cause 
a cross-site scripting attack. This issue was only addressed in Ubuntu 16.04 LTS.
(CVE-2017-6820)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly restrict exec call in 
certain drivers of the password plugin. An authenticated user could possibly 
use this issue to perform arbitrary password resets. This issue was only addressed in 
Ubuntu 16.04 LTS. (CVE-2017-8114)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly set file permissions within 
the Enigma plugin. An attacker could possibly use this issue to exfiltrate GPG private 
keys via network connectivity. (CVE-2018-1000071)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly handle GnuPG MDC 
integrity-protection warnings. An attacker could possibly use this issue to obtain 
sensitive information from encrypted communications. (CVE-20…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: roundcube, Ubuntu:Pro:18.04:LTS: roundcube&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly sanitize 
certain HTML elements within the e-mail body. An attacker could possibly 
use this issue to cause a cross-site scripting attack. This issue was only 
addressed in Ubuntu 16.04 LTS. (CVE-2016-4068, CVE-2016-4069)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly handle certain 
configuration parameters. An attacker could possibly use this issue to 
execute arbitrary code. This issue was only addressed in Ubuntu 16.04 LTS. 
(CVE-2016-9920)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly sanitize CSS styles 
within SVG documents. An attacker could possibly use this issue to cause 
a cross-site scripting attack. This issue was only addressed in Ubuntu 16.04 LTS.
(CVE-2017-6820)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly restrict exec call in 
certain drivers of the password plugin. An authenticated user could possibly 
use this issue to perform arbitrary password resets. This issue was only addressed in 
Ubuntu 16.04 LTS. (CVE-2017-8114)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly set file permissions within 
the Enigma plugin. An attacker could possibly use this issue to exfiltrate GPG private 
keys via network connectivity. (CVE-2018-1000071)&lt;/p&gt;
&lt;p&gt;It was discovered that Roundcube Webmail did not properly handle GnuPG MDC 
integrity-protection warnings. An attacker could possibly use this issue to obtain 
sensitive information from encrypted communications. (CVE-20…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8132-1</guid>
    </item>
  </channel>
</rss>
