Vulnerabilities (CVE)

Filtered by vendor Horde Subscribe
Filtered by product Imp
Total 21 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4080 1 Horde 1 Imp 2025-04-03 4.3 MEDIUM N/A
Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.