Commit Graph

2080 Commits (5b7e9a2c960eb4fd2364921297020a5dcd2d7dbc)

Author SHA1 Message Date
Thomas Bruederli 5b7e9a2c96 Fix check_request() bypass in places using get_uids() (#6238)
[CVE-2018-9846]
7 years ago
Thomas Bruederli cdeb6234a2 Fix possible IMAP command injection vulnerability (#6229)
[CVE-2018-9846]
7 years ago
Aleksander Machniak 8e7c2f61a3 Fix bug in remote content blocking on HTML image and style tags (#6178) 7 years ago
Thomas Bruederli 987856eee2 Bump version + add CVE ID 7 years ago
Aleksander Machniak c68f81e01d Update changelog 7 years ago
Aleksander Machniak 24edb8de3e Fix parsing dot-staffed lines in multiline text (#5838) 7 years ago
Aleksander Machniak 1fd9ad242e Fix (again) bug where image data URIs in css style were treated as evil/remote in mail preview (#5580) 7 years ago
Aleksander Machniak ead587ad59 Fix bug where HTML messages could have been rendered empty on some systems (#5957)
Consistently use $nodeName instead of $tagName property.
7 years ago
Aleksander Machniak b786599fb0 Update changelog 7 years ago
Thomas Bruederli 3644b02d0b Bump version to 1.2.6 7 years ago
Thomas Bruederli 5fd704ac9e Update Changelog 7 years ago
Aleksander Machniak f9151f6830 Managesieve: Fix AM/PM suffix in vacation time selectors 8 years ago
Aleksander Machniak 822afb7afd Update changelog 8 years ago
Aleksander Machniak 183f68f387 Fix uninitialized string offset in rcube_utils::bin2ascii() and make sure rcube_utils::random_bytes() result has always requested length (#5788) 8 years ago
Aleksander Machniak 3d498cd632 Fix bug where it wasn't possible to set timezone to auto-detected value (#5782) 8 years ago
Aleksander Machniak 913ffcfbbe Fix SQL syntax error on MariaDB 10.2 (#5774) 8 years ago
Aleksander Machniak 793bf96747 Enigma: Fix compatibility with assets_dir 8 years ago
Aleksander Machniak 58d7cdc3fc Fix addressbook searching by gender (#5757) 8 years ago
Aleksander Machniak 1b8d766447 Fix bug where it wasn't possible to scroll folders list in Edge (#5750) 8 years ago
Aleksander Machniak 9bfacb4d3c Fix bug where comment notation within style tag would cause the whole style to be ignored (#5747) 8 years ago
Thomas Bruederli e62a7d0dfa Bump version to 1.2.5 8 years ago
Aleksander Machniak fc557cacfa Add CVE ident 8 years ago
Aleksander Machniak 6e054a37d1 Password: Fix security issue in virtualmin and sasl drivers 8 years ago
Aleksander Machniak 22b34fc44b Fix bug where base_dn setting was ignored inside group_filters (#5720) 8 years ago
Thomas Bruederli 00874b7fbd Add CVE identifier to recent XSS fix 8 years ago
Aleksander Machniak cc3b79bf66 Fix re-positioning of the fixed header of messages list in Chrome when using minimal mode toggle and About dialog (#5711) 8 years ago
Aleksander Machniak b213ee9aa0 Merge branch 'release-1.2' of github.com:roundcube/roundcubemail into release-1.2 8 years ago
Aleksander Machniak 2f6ca6d672 Fix bug where namespace prefix could not be truncated on folders list if show_real_foldernames=true (#5695) 8 years ago
Aleksander Machniak 0fffea28c1 Fix regression in LDAP fuzzy search where it always used prefix search instead (#5713) 8 years ago
Aleksander Machniak d5be34ad17 Update changelog 8 years ago
Aleksander Machniak fa62496107 Fix so settings/upload.inc could not be used by plugins (#5694) 8 years ago
Aleksander Machniak fa2824fdcd Fix XSS issue in handling of a style tag inside of an svg element 8 years ago
Aleksander Machniak 33586e4c87 Fix possible defect in handling \r\n in scripts (#5685) 8 years ago
Thomas Bruederli 85a750a068 Bump version to 1.2.4 8 years ago
Aleksander Machniak 04ed3846d3 Managesieve: Fix parser issue with empty lines between comments (#5657) 8 years ago
Aleksander Machniak 801f296872 Fix bug where it was too easy accidentally move a folder when using the subscription checkbox (#5655) 8 years ago
Aleksander Machniak e3484f9225 Add rewrite rule to disable access to /vendor/bin folder in .htaccess (#5630) 8 years ago
Aleksander Machniak b1a5b76445 Fix update of group name in the contacts list header on group rename (#5648) 8 years ago
Aleksander Machniak 49d24e973d Enigma: Fix handling of messages with nested PGP encrypted parts (#5634) 8 years ago
Aleksander Machniak 4bc337c460 Enigma: Fix missing require statement for Crypt_GPG_KeyGenerator (#5641) 8 years ago
Aleksander Machniak f51a101891 Fix regression where groups with email address were resolved to its members' addresses 8 years ago
Aleksander Machniak a336026142 Fix bug where signature couldn't be added above the quote in Firefox 51 (#5628) 8 years ago
Aleksander Machniak 9e75845193 Fix bug where some classic skin images were not displayed in IE/Edge (#5614)
Converted from png to gif according to file extension.
8 years ago
Aleksander Machniak 04025fb297 Fix bug where mail content frame couldn't be reset in some corner cases (#5608)
Conflicts:
	CHANGELOG
8 years ago
Aleksander Machniak 82b826faef Fix PHP error on update of a contact with multiple email addresses when using PHP 7.1 (#5587) 8 years ago
Aleksander Machniak 1568bd9e04 Fix bug where external content in src attribute of input/video tags was not secured (#5583) 8 years ago
Aleksander Machniak f90f22ffb8 Fix bug where image data URIs in css style were treated as evil/remote in mail preview (#5580) 8 years ago
Aleksander Machniak 58e63a6e70 Fix so group/addressbook selection is retained on page refresh 8 years ago
Aleksander Machniak c9b394bcad Fix some advanced search issues with multiple addressbooks (#5572) 8 years ago
Aleksander Machniak 088b0c6e85 Fix rsync error handling in installto.sh script (#5562) 8 years ago