1038 Commits (37e2bc745723ef6322f0f785aefd0b9313a40f19)

Author SHA1 Message Date
Thomas Bruederli fe0d97e5e0 Bump version to 1.3.11 5 years ago
Aleksander Machniak c0eea755cf Fix local file inclusion (and code execution) via crafted 'plugins' option 5 years ago
Aleksander Machniak 47f431b1d6 Fix remote code execution via crafted 'im_convert_path' or 'im_identify_path' settings 5 years ago
Aleksander Machniak 23c06159ae Fix XSS issue in handling of CDATA in HTML messages 5 years ago
Aleksander Machniak 3483c6407f Fix PHP Warning: Use of undefined constant LOG_EMERGE (#6991) 6 years ago
Aleksander Machniak e97837ba21 Fix bug where inline images could have been ignored if Content-Id header contained redundant spaces (#6980) 6 years ago
Aleksander Machniak 4683204ddf Fix PHP Warning: Redis::connect() expects parameter 2 to be int, string given 6 years ago
Aleksander Machniak 0132ff0d85 Fix PHP 7.4 warning: "Creating default object from empty value" 6 years ago
Aleksander Machniak 2348899a3f Fix bug where it was possible to bypass href URI check with data:application/xhtml+xml URIs (#6896) 6 years ago
Aleksander Machniak 554a20fe49 Fix security issue where it was possible to bypass the CSS jail in HTML messages using :root pseudo-class (#6897) 6 years ago
Aleksander Machniak c0c42d1075 Fix bug where some strict remote URIs in url() style were unintentionally blocked (#6899) 6 years ago
Aleksander Machniak d0d8c1ace5 Fix security issue where it was possible to bypass the position:fixed CSS check in received messages (#6898) 6 years ago
Thomas Bruederli f2e610dbe5 Bump version to 1.3.10 6 years ago
Jack Cherng 45e099b0be Fix implode() wrong parameter order (#6866) 6 years ago
Aleksander Machniak 42c473aedd Fix wrong messages order after returning to a multi-folder search result (#6836) 6 years ago
Aleksander Machniak 22375170df Fix bug in converting multi-page Tiff images into Jpeg (#6824) 6 years ago
Aleksander Machniak 1cd1990053 Fix PHP error when using Net_LDAP3 from master 6 years ago
Amir Caspi 06c5a20331 Update rcube_utils::parse_host, fixes #6746 6 years ago
Aleksander Machniak 55ebae3c1e Fix bug where bold/strong text was converted to upper-case on html-to-text conversion (6758) 6 years ago
Aleksander Machniak 8b706775f3 Fix bug in parsing vCard data using PHP 7.3 due to an invalid regexp (#6744) 6 years ago
Aleksander Machniak 9cb1912553 Fix bug where bmp images couldn't be displayed on some systems (#6728) 6 years ago
Aleksander Machniak 7b8a183e9f Bump version to 1.3.9 6 years ago
Aleksander Machniak 1d7b488841 Fix so ANY record is not used for email domain validation, use A, MX, CNAME, AAAA instead (#6581) 7 years ago
Aleksander Machniak 1418812c89 Fix bug in parsing some IMAP command responses that include unsolicited replies (#6577) 7 years ago
Aleksander Machniak eec0d76360 Fix regression in vcard parser 7 years ago
Aleksander Machniak 8dec8fb60a Fix handling of empty entries in vCard import (#6564) 7 years ago
Aleksander Machniak 4619f030f2 Fix bug where a message/rfc822 part without a filename wasn't listed on the attachments list (#6494) 7 years ago
Thomas Bruederli b1a8a4b627 Bump version to 1.3.8 7 years ago
Aleksander Machniak a34a206b60 Fix session issue on long running requests (#6470) 7 years ago
Stefanos Petrakis e3f6d4184f Fix multiple VCard field search (#6466) 7 years ago
Aleksander Machniak c22c177e53 Fix bug where valid content between HTML comments could have been skipped in some cases (#6464) 7 years ago
Aleksander Machniak 4303c59467 New_user_identity: Fix %fu/%u vars substitution in user specific LDAP params (#6419) 7 years ago
Aleksander Machniak 8b6da9a65a Fix invalid regular expressions that throw warnings on PHP 7.3 (#6398) 7 years ago
Aleksander Machniak d8a1f99db9 Fix so fallback from BINARY to BODY FETCH is used also on [PARSE] errors in dovecot 2.3 (#6383) 7 years ago
Aleksander Machniak a411d8cb87 Fix PHP warnings on dummy QUOTA responses in Courier-IMAP 4.17.1 (#6374) 7 years ago
Thomas Bruederli 9f79a7ae6f Bump version to 1.3.7 7 years ago
Aleksander Machniak 2e3648b24f Fix bug where some HTML comments could have been malformed by HTML parser (#6333) 7 years ago
Aleksander Machniak e5050f8087 Fix bug where after "mark all folders as read" action message counters were not reset (#6307) 7 years ago
Aleksander Machniak e8de88ac74 Fix bug where unicode contact names could have been broken/emptied or caused DB errors (#6299) 7 years ago
Aleksander Machniak 16b5a345e0 Fix bug where some forbidden characters on Cyrus-IMAP were not prevented from use in folder names 7 years ago
Aleksander Machniak 616e130bc4 Add sanity check when auto-unsubscribing non-existing folders 8 years ago
Aleksander Machniak d9eed3625b Fix bug where some escape sequences in html styles could bypass security checks 7 years ago
Edgaras L 7dfbb62b78 Parse all quotas from GETQUOTAROOT (#6280) 7 years ago
Aleksander Machniak 8477b881e5 Fix PHP Warning: Use of undefined constant IDNA_DEFAULT on systems without php-intl (#6244) 7 years ago
Thomas Bruederli 357f9380c3 Bump version to 1.3.6 7 years ago
Aleksander Machniak c278b8796f Fix bug where usernames without domain part could be malformed or converted to lower-case on logon (#6224) 7 years ago
Aleksander Machniak dc9c9c36a8 Fix regression in compressMessageSet() (#6235) 7 years ago
Aleksander Machniak 77d447ff7c Fix possible IMAP command injection and type juggling vulnerabilities (#6229) 7 years ago
Aleksander Machniak 9efd534fe1 Fix PHP 7.2: count(): Parameter must be an array in enchant-based spellchecker (#6234) 7 years ago
Aleksander Machniak 60902de521 Fix parsing date strings (e.g. from a Date: mail header) with comments (#6216) 7 years ago