Retour à la veille
CVE-2026-74998
Score CVSS
7.2
HIGH
Description détaillée
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
Vecteur d'attaque (CVSS)
Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Références et Patchs
https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43bhttps://github.com/roundcube/roundcubemail/commit/a2334990c02f7cb77b1a8d6fa97fcd9e1b5cd1fbhttps://github.com/roundcube/roundcubemail/releases/tag/1.6.18https://github.com/roundcube/roundcubemail/releases/tag/1.7.3https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
Dernières Vulnérabilités
CVE-2026-75060
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
VOIR DÉTAILS
CVE-2026-75059
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
VOIR DÉTAILS
CVE-2026-75058
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
VOIR DÉTAILS
