MidnightBSD

Advisories for 9folders

CVE-2017-17689 MEDIUM

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
google gmail -
ibm notes -
kde kmail -
emclient emclient -
flipdogsolutions maildroid -
mozilla thunderbird -
bloop airmail -
postbox-inc postbox -
microsoft outlook 2016
freron mailmate -
microsoft outlook 2007
microsoft outlook 2013
apple mail -
horde horde_imp -
9folders nine -
microsoft outlook 2010
r2mail2 r2mail2 -
kde trojita -
gnome evolution -
ritlabs the_bat -
CVE-2019-12366 MEDIUM

The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
9folders nine *