Kolab develops a focused groupware and collaboration server platform that consolidates email, calendaring, and contact management for organizations. The recurring disclosures cluster around its server offerings, though the underlying weakness characterization in available reports remains incomplete or placeholder categories. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kolab over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4824HIGH Unspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server before 2.2.3 allows attackers to have an unspecified impact via vectors related to an "image upload form." | Apr 27, 2010 | 7.5 | 22 | NO | NO |
CVE-2005-4828MEDIUM Kolab Server 2.0.0 and 2.0.1 does not properly handle when a large email is sent with a "." in the wrong place, which causes kolabfilter to add another ".", which might break clear | Dec 31, 2005 | 6.4 | 17 | NO | NO |
CVE-2008-4165MEDIUM admin/user/create_user.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows local administrators, and possibly remote attackers, to obtai | Sep 22, 2008 | 4.0 | 14 | NO | NO |
CVE-2007-4510MEDIUM ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RT | Aug 23, 2007 | 4.3 | 14 | NO | NO |
CVE-2006-0213MEDIUM Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the po | Jan 14, 2006 | 4.6 | 14 | NO | NO |
CVE-2004-1997MEDIUM Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges. | May 5, 2004 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kolab.
Media articles that mention a CVE ID that affects a product developed by Kolab — matched by CVE ID, not by vendor name.