Known Vulnerabilities for products from Citadel
Listed below are 16 of the newest known vulnerabilities associated with the vendor "Citadel".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-44272 json | A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant message ... | 5.4 - MEDIUM | 2023-10-04 | 2023-10-10 |
| CVE-2021-37845 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 3.7 - LOW | 2023-05-29 | 2023-06-05 |
| CVE-2020-29547 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.9 - MEDIUM | 2023-05-29 | 2023-06-05 |
| CVE-2020-27742 json | An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read... | 6.5 - MEDIUM | 2020-10-28 | 2020-11-04 |
| CVE-2020-27741 json | Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary ... | 6.1 - MEDIUM | 2020-10-28 | 2020-11-04 |
| CVE-2020-27740 json | Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform. NOTE: this w... | 5.3 - MEDIUM | 2020-10-28 | 2020-11-04 |
| CVE-2020-27739 json | A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recen... | 9.8 - CRITICAL | 2020-10-28 | 2020-11-04 |
| CVE-2011-1756 json | modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows... | Not Provided | 2011-06-21 | 2026-04-29 |
| CVE-2009-0364 json | Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows... | Not Provided | 2009-03-26 | 2026-04-23 |
| CVE-2008-0394 json | Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO ... | Not Provided | 2008-01-23 | 2026-04-23 |
| CVE-2007-3822 json | Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web scri... | Not Provided | 2007-07-17 | 2026-04-23 |
| CVE-2007-3821 json | Cross-site request forgery (CSRF) vulnerability in Webcit before 7.11 allows remote attackers to modify configurations and pe... | Not Provided | 2007-07-17 | 2026-04-23 |
| CVE-2004-1933 json | Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local u... | Not Provided | 2004-04-12 | 2025-04-03 |
| CVE-2004-1705 json | Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username. | Not Provided | 2004-07-30 | 2025-04-03 |
| CVE-2004-1192 json | Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitra... | Not Provided | 2005-01-10 | 2025-04-03 |
| CVE-2002-0432 json | Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a ... | Not Provided | 2002-07-26 | 2025-04-03 |
Known software with vulnerabilities from Citadel
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Citadel | Hercules | - |
| Application | Citadel | Hercules Remediation Client For Windows | 3.5.1 |
| Application | Citadel | Smtp | - |
| Application | Citadel | Ux | - |
| Application | Citadel | Webcit | - |