7418 Commits (0b42424e41e1e7d23fc516bf841633c5ff0971fd)
 

Author SHA1 Message Date
Thomas Bruederli 0b42424e41 Bump version + add CVE ID 8 years ago
Aleksander Machniak 4f5d8ab015 Update changelog 8 years ago
Aleksander Machniak 8d87bb34f3 Fix file disclosure vulnerability caused by insuficient input validation in relation with attachment plugins (#6026) 8 years ago
Thomas Bruederli ca74231733 Bump version to 1.0.11 8 years ago
Aleksander Machniak 62edcc6283 Add CVE ident 8 years ago
Aleksander Machniak 271426429b Password: Fix security issue in virtualmin and sasl drivers 8 years ago
Thomas Bruederli 511793c25f Update Changelog + bump version to 1.0.10 8 years ago
Thomas Bruederli 37cae3ecfa Strip HTML tags inside CSS style definitions 8 years ago
Aleksander Machniak a54dde834c Fix vulnerability in handling of mail()'s 5th argument 9 years ago
Aleksander Machniak 5d2aaa68c3 Fix _from argument validation 9 years ago
Aleksander Machniak dc0c6067b7 Update changelog 9 years ago
Aleksander Machniak 1e275ac13a Wash position:fixed style in HTML mail for better security (#5264) 9 years ago
Aleksander Machniak f1ca20d993 Don't create multipart/alternative messages with empty text/plain part (#5283) 9 years ago
Thomas Bruederli 7b37ef8a33 Avoid sending completely empty text parts for multipart/alternative messages (#5283) 9 years ago
Aleksander Machniak acf633c73b Fix XSS issue in href attribute on area tag (#5240, #5241) 9 years ago
Thomas Bruederli cde7a9eb74 Bump version to 1.0.9 9 years ago
Thomas Bruederli b76d8e91d6 Transliterate ticket IDs after migration to Github issues 9 years ago
Aleksander Machniak 74c75ee529 Refer to Github issues instead of Trac 9 years ago
Thomas Bruederli fca89f0e77 Refer to Github issues instead of Trac 9 years ago
Aleksander Machniak 10f24c034b Hide DSN option in Preferences when smtp_server is not used (#1490666) 10 years ago
Aleksander Machniak 3c988b0f08 Update changelog 10 years ago
Aleksander Machniak 5466f71dd6 Fix a regression where some contact data was missing in export and PHP warnings were logged (Kolab #4522) 11 years ago
Aleksander Machniak efe06f2b12 Bring back additional_message_headers compatibility with Mail_Mime < 1.9 10 years ago
Aleksander Machniak b2d4cfa89a Fix additional_message_headers plugin compatibility with Mail_Mime >= 1.9 (#1490657) 10 years ago
Aleksander Machniak 3e12784cc2 Fix bug in long recipients list parsing for cases where recipient name contained @-char (#1490653) 10 years ago
Aleksander Machniak 7496302945 Fix bug where Archive/Junk buttons were not active after page jump with select=all mode (#1490647) 10 years ago
Aleksander Machniak a7fac6afb6 Fix (again) security issue in DBMail driver of password plugin [CVE-2015-2181] (#1490643) 10 years ago
Aleksander Machniak 889989db06 Fix regression where xml mode could be used to parse xhtml messages causing empty result 10 years ago
Aleksander Machniak 73f8b524f3 Improved SVG cleanup code 10 years ago
Aleksander Machniak 190c658fe3 Refactor wash_attribs() - fix regressions 10 years ago
Aleksander Machniak ffd5ffc30a Extend rcube_washtml with SVG support 10 years ago
Aleksander Machniak 3faf89c354 Fix XSS issue in SVG images handling (#1490625) 10 years ago
Francis Russell e77b5f7dd7 Make TLS method for IMAP parameterisable. 10 years ago
Francis Russell 6a70e56e5e Enable use of TLSv1.1 and TLSv1.2 for IMAP. 10 years ago
Thomas Bruederli 2c0a550105 Bump version to 1.0.8; update Changelog 10 years ago
Aleksander Machniak 222f47c042 Fix .htaccess rewrite rules to not block .well-known URIs (#1490615) 10 years ago
Aleksander Machniak 82fcd4e757 Fix so drag-n-drop of text (e.g. recipient addresses) on compose page actually works (#1490619) 10 years ago
Aleksander Machniak 21b523c29b Fix path traversal vulnerability in setting a skin (#1490620) 10 years ago
Aleksander Machniak 50403d66e0 Fix PDF support detection in Firefox > 19 (#1490610) 10 years ago
Aleksander Machniak 5579ef6621 Fix handling of message/rfc822 attachments on replies and forwards (#1490607) 10 years ago
Aleksander Machniak 6402eb7f78 Fix charset encoding of message/rfc822 part bodies (#1490606) 10 years ago
Aleksander Machniak e7d1a80a80 Fix HTML sanitizer to skip <!-- node type X --> in output (#1490583) 10 years ago
Aleksander Machniak 48ab1add35 Add workaround for https://bugs.php.net/bug.php?id=70757 (#1490582) 10 years ago
Thomas Bruederli 7bd7d60add Bump version to 1.0.7 10 years ago
Aleksander Machniak 969547784e Fix issue where Content-Length of some attachments could be set to wrong value causing browser errors (#1490482) 10 years ago
Aleksander Machniak 4ec947715d Fix XSS issue in drag-n-drop file uploads (#1490530) 10 years ago
Aleksander Machniak 175ca6fd65 Fix so In-Reply-To header is set also for MDN receipts (#1490523) 10 years ago
Aleksander Machniak 98a61c74ee Fix various issues with Turkish (and similar) locales (#1490519) 10 years ago
Aleksander Machniak 3b59a32026 Fix support for Mozilla-based browsers, e.g. Pale Moon (#1490517) 10 years ago
Aleksander Machniak e6939619f7 Fix so gc.sh script removes also expired sessions from sql database (#1490512) 10 years ago