« Volver al listado

CVE-2010-0464

Estado: ModificadaMedia (5)—

Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-0464",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-01-29T18:30:01.137",
  "references": [
    {
      "url": "http://trac.roundcube.net/ticket/1486449",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:048",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://trac.roundcube.net/ticket/1486449",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:048",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests."
    },
    {
      "lang": "es",
      "value": "Roundcube v0.3.1 y anteriores no solicitan que el navegador web permita el \"prefetching\" DNS de los nombres de dominio contenidos en mensajes de correo electrónico, lo que facilita a atacantes remotos determinar la localización de red del usuario de webmail mediante peticiones de logggin DNS."
    }
  ],
  "lastModified": "2026-06-16T23:16:13.880",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12C3ED93-48DB-4220-8416-DB138ED87630",
              "versionEndIncluding": "0.3.1"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C785B00-7F4D-4EBD-A9FA-726D4D35E5D1"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1:20050811:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E525B8F-ED49-494A-A9C1-CCFFDCFAAA11"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1:20050820:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9C38F5E-A79B-45F4-AD0C-894DE7ADD8EE"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1:20051007:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BDB7224-1922-41BC-82F1-187DEEEE60DA"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1:20051021:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9019C121-5D96-4967-92FA-AA63FAD40435"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1:alpha:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F433741-5F73-43B5-A522-C484C64C66A7"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09DF755B-041E-4A61-BEF6-A613F6F0CE13"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34D20437-7DE7-4DB8-8C11-37B09A87E3A4"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55FB4AA3-3528-46B7-BBB9-9185DAA5425C"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "066AA2BC-95A8-43E8-A1FE-9F15860691E1"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1:stable:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BADA5A07-C90D-4000-A973-0A918E390D5F"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82FB886B-35A4-4A8C-AE18-62C845886018"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83FF6973-9BAC-4DF2-BACE-42F0D9340A27"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.2:alpha:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB6449FD-C6EE-497C-BE34-88900883AD09"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.2:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0CEF8BF6-E09F-4376-B089-9B722A84F591"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.2:stable:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84126D1E-F709-4F23-A541-B92B6ED01D3D"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "946B0B6A-46D3-46B9-BD1E-B03D3339EEB3"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D572A44-701A-4D6F-919F-AB8AE4BF4417"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4D6EA96-EE58-47C3-B545-7238B3F64941"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.3:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3584BB62-818D-4A5B-BC7D-EAB0B85614EA"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.3:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "332FF744-3682-4818-9602-8F868BF0781E"
            },
            {
              "criteria": "cpe:2.3:a:roundcube:webmail:0.3:stable:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "141BFB80-F895-482C-B2ED-A6FB9135EA9B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}