← Back

CVE-2014-0079

nvd nist
Published: Apr 28, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the password."

Affected (15)

Products: Zarafa: Zarafa
1 product
Zarafa
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Zarafa
Up to 6.20
Version 5.00
Version 5.01
Version 5.02
Version 5.10
Version 5.11
Version 5.20
Version 5.22
Version 6.00
Version 6.01
Version 6.02
Version 6.03
Version 6.10
Version 6.11
Version 7.1.8

References (4)

Timeline

No history available yet.