CVE-2015-2181: Roundcube Webmail
High severity, CVSS 8.8. EPSS: 2.9% chance of exploitation in the next 30 days.
Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.
Affected products
- Roundcube Webmail: before 1.1.0 (fixed in 1.1.0)
Published 2017-01-30. Last modified 2026-06-17.