CVE-2009-4363

Text_Filter/lib/Horde/Text/Filter/Xss.php in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 does not properly handle data: URIs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via data:text/html values for the HREF attribute of an A element in an HTML e-mail message.  NOTE: the vendor states that the issue is caused by "an XSS vulnerability in Firefox browsers."
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
hordeapplication_framework
𝑥
≤ 3.3.5
hordeapplication_framework
2.0
hordeapplication_framework
2.1
hordeapplication_framework
2.1.3
hordeapplication_framework
2.2
hordeapplication_framework
2.2.1
hordeapplication_framework
2.2.3
hordeapplication_framework
2.2.4
hordeapplication_framework
2.2.4_rc1:_rc1
hordeapplication_framework
2.2.5
hordeapplication_framework
2.2.6
hordeapplication_framework
3.0
hordeapplication_framework
3.0.1
hordeapplication_framework
3.0.2
hordeapplication_framework
3.0.3
hordeapplication_framework
3.0.4
hordeapplication_framework
3.0.6
hordeapplication_framework
3.0.7
hordeapplication_framework
3.0.8
hordeapplication_framework
3.0.9
hordeapplication_framework
3.1
hordeapplication_framework
3.1.1
hordeapplication_framework
3.2
hordeapplication_framework
3.2.1
hordeapplication_framework
3.2.2
hordeapplication_framework
3.2.3
hordeapplication_framework
3.2.4
hordeapplication_framework
3.3
hordeapplication_framework
3.3.1
hordeapplication_framework
3.3.2
hordeapplication_framework
3.3.3
hordeapplication_framework
3.3.4
hordegroupware
𝑥
≤ 1.2.4
hordegroupware
1.0
hordegroupware
1.0.1
hordegroupware
1.0.2
hordegroupware
1.0.3
hordegroupware
1.0.4
hordegroupware
1.0.5
hordegroupware
1.1
hordegroupware
1.1.1
hordegroupware
1.1.2
hordegroupware
1.1.3
hordegroupware
1.1.4
hordegroupware
1.1.5
hordegroupware
1.2
hordegroupware
1.2:rc1
hordegroupware
1.2.1
hordegroupware
1.2.2
hordegroupware
1.2.3
hordegroupware
𝑥
≤ 1.2.4
hordegroupware
1.0
hordegroupware
1.0:rc1
hordegroupware
1.0:rc2
hordegroupware
1.0.1
hordegroupware
1.0.2
hordegroupware
1.0.3
hordegroupware
1.0.4
hordegroupware
1.0.5
hordegroupware
1.0.6
hordegroupware
1.0.7
hordegroupware
1.0.8
hordegroupware
1.1
hordegroupware
1.1:rc1
hordegroupware
1.1:rc2
hordegroupware
1.1:rc3
hordegroupware
1.1:rc4
hordegroupware
1.1.1
hordegroupware
1.1.2
hordegroupware
1.1.3
hordegroupware
1.1.4
hordegroupware
1.1.5
hordegroupware
1.1.6
hordegroupware
1.2
hordegroupware
1.2:rc1
hordegroupware
1.2.1
hordegroupware
1.2.2
hordegroupware
1.2.3
hordegroupware
1.2.3:rc1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
horde3
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
ignored
jaunty
Fixed 3.2.2+debian0-2+lenny2build0.9.04.1
released
intrepid
ignored
hardy
ignored
dapper
ignored