CVE-2014-9465: Fedoraproject Fedora

Medium severity, CVSS 5.0. EPSS: 3.4% chance of exploitation in the next 30 days.

senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.2.0 beta 1 allows remote attackers to cause a denial of service (/tmp disk consumption) by uploading a large number of files.

Affected products

  • Fedoraproject Fedora: version 20 only; version 21 only
  • Zarafa Webapp: up to and including 2.0
  • Zarafa Zarafa Collaboration Platform: version 7.0.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; version 7.0.5 only; …

Published 2015-02-19. Last modified 2026-06-17.