Commit Graph

6629 Commits (e3dd5b66d236867572e68fcb80281e9268a0cfb0)

Author SHA1 Message Date
Aleksander Machniak e3dd5b66d2 Fix check_request() bypass in places using get_uids() [CVE-2018-9846] (#6238) 7 years ago
Aleksander Machniak dc9c9c36a8 Fix regression in compressMessageSet() (#6235) 7 years ago
Aleksander Machniak 77d447ff7c Fix possible IMAP command injection and type juggling vulnerabilities (#6229) 7 years ago
Aleksander Machniak 9efd534fe1 Fix PHP 7.2: count(): Parameter must be an array in enchant-based spellchecker (#6234) 7 years ago
Aleksander Machniak 60902de521 Fix parsing date strings (e.g. from a Date: mail header) with comments (#6216) 7 years ago
Thomas Bruederli 8922e3e076 Bump version to 1.3.5 7 years ago
Aleksander Machniak f55724d1e8 Fix bug where some unix timestamps were not handled correctly by rcube_utils::anytodatetime() (#6212) 7 years ago
Aleksander Machniak e5b7bcd207 Fix handling encoding of HTML tags in "inline" JSON output (#6207) 7 years ago
Aleksander Machniak 8565b51059 Added 9pt and 11pt to the list of font sizes in HTML editor 7 years ago
Aleksander Machniak b8e51b9d2f Remove redundant trim() 7 years ago
Aleksander Machniak 24dcdb5414 Fix bug in remote content blocking on HTML image and style tags (#6178) 7 years ago
Aleksander Machniak 96f792c1f2 Fix PHP Warning: exif_read_data(...): Illegal IFD size (#6169) 7 years ago
Aleksander Machniak 78d896d469 Fix PHP 7.2 warning: count(): Parameter must be an array or an object that implements Countable 7 years ago
Aleksander Machniak 0f06f58e52 Fix possible information leak - add more strict sql error check on user creation (#6125) 7 years ago
Aleksander Machniak 2eeb2c75df Fix bug where contacts search could skip some records (#6130)
Conflicts:
	CHANGELOG
7 years ago
Thomas Bruederli 917ae1c199 Bump version to 1.3.4 7 years ago
Aleksander Machniak 6fb6a0b885 Update localization 7 years ago
Aleksander Machniak f9c590621b Remove x_frame_options env 7 years ago
Aleksander Machniak 65da434867 Fix X-Frame-Options:ALLOW-FROM support, remove custom click-jacking protection (#6057) 7 years ago
Richard Hillmann b9c038ca63 Fix preg_match in guess_type function (#6123) 7 years ago
Aleksander Machniak 55ba350102 - Fix searching contacts by address in LDAP source (#6084) 7 years ago
Aleksander Machniak d15c6872cb Fix PHP 7.2: count(): Parameter must be an array or an object that implements Countable (#6098) 7 years ago
Aleksander Machniak 1c10231b26 Fix bug where contacts export by selection returned no more than 10 entries (#6103) 7 years ago
Aleksander Machniak 472e48ff0d Fix possible performance issue when parsing malformed and long Date header (#6087) 7 years ago
Aleksander Machniak cdf7a88b3e Fix PHP Warning: Use of undefined constant INTL_IDNA_VARIANT_UTS46 on servers without php-intl extension 7 years ago
Aleksander Machniak a315f2b16d Fix PHP warning "idn_to_utf8(): INTL_IDNA_VARIANT_2003 is deprecated" with PHP 7.2 (#6075) 7 years ago
Aleksander Machniak 1765e855c9 Fix untagged COPYUID responses handling - again (#5982) 7 years ago
Aleksander Machniak 6be149655f Fix PHP Warning: Use of undefined constant 'href' 7 years ago
Aleksander Machniak 0c56b5d4c0 Fix broken long filenames when using imap4d server - workaround server bug (#6048) 7 years ago
Aleksander Machniak 4b29748161 Fix var scope (#6042) 7 years ago
Thomas Bruederli d84391d2c8 Bump version + add CVE ID 7 years ago
Aleksander Machniak 46faac4a6e Fix mangled non-ASCII characters in links in HTML messages (#6028) 7 years ago
Aleksander Machniak c90ad5a977 Fix file disclosure vulnerability caused by insuficient input validation in relation with attachment plugins (#6026) 7 years ago
Aleksander Machniak a9170f652c Fix decoding of mailto: links with + character in HTML messages (#6020) 7 years ago
Thomas Bruederli 2c7f3751ab Update localization files from Transifex 7 years ago
Thomas Bruederli 7be09964f2 Update translations for new label 'automarkread'
issue #5952
7 years ago
Thomas Bruederli 3762dba408 Fix rcube_utils::random_bytes() to not throw exception for length=0 7 years ago
Thomas Bruederli 392f88afc1 Bump version to 1.3.2 7 years ago
Aleksander Machniak 6113300676 Prevent from ghost messages on list after fast delete of multiple messages one-by-one (#5941) 7 years ago
Aleksander Machniak c1d282ec54 Fix bug where removing the last subfolder did not hide toggle button on its parent record (#6007) 7 years ago
Aleksander Machniak eb62e15b22 Fix truncated folder name on messages list in multi-folder mode, for folders with non-ascii characters (#6004) 7 years ago
Brendan Braybrook 6843668b2b fix: unknown content-disposition type should be treated as attachment (#6002) 7 years ago
Aleksander Machniak 5e31411819 Fix regression in qsearch() that skipped execution when called with no args
Some plugins would like to do search without value,
so we keep value != '' check to allow that use-case.
7 years ago
Aleksander Machniak 8ba12b0a8d Fix Edge encoding bug when pasting text into the HTML editor, update to TinyMCE 4.5.8 (#5885) 7 years ago
Aleksander Machniak 1bb97973b2 Fix issue caused by non-default session.cookie_lifetime setting (#5961) 7 years ago
Aleksander Machniak b07a5e539f Fix so untagged COPYUID responses are also supported according to RFC6851 (#5982) 7 years ago
Aleksander Machniak 0ad7e4c903 Fix bug where assets_path wasn't added to some watermark frames 7 years ago
Aleksander Machniak 305900b4c3 Fix bug where mail search could return empty result on servers without SORT capability (#5973) 7 years ago
Aleksander Machniak 972be07a41 Fix (again) bug where image data URIs in css style were treated as evil/remote in mail preview (#5580) 7 years ago
Aleksander Machniak 398a43e9a4 Fix missing cursor in HTML editor on mail reply (#5969) 7 years ago