← Back

CVE-2015-8078

nvd nist
Published: Dec 3, 2015Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.

Affected (43)

Products: Opensuse: Leap, Opensuse · Cyrus: Imap
2 products
Leap
Opensuse
1 product
Imap
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 42.1
Version 13.2
Configuration B
41 vulnerable
Vulnerable SoftwareAffected Versions
Cyrus
Version 2.3.0
Version 2.3.10
Version 2.3.11
Version 2.3.12
Version 2.3.13
Version 2.3.14
Version 2.3.15
Version 2.3.16
Version 2.3.17
Version 2.3.18
Version 2.3.1
Version 2.3.2
Version 2.3.3
Version 2.3.4
Version 2.3.5
Version 2.3.6
Version 2.3.7
Version 2.3.8
Version 2.3.9
Version 2.4.0
Version 2.4.10
Version 2.4.11
Version 2.4.12
Version 2.4.13
Version 2.4.14
Version 2.4.15
Version 2.4.16
Version 2.4.17
Version 2.4.1
Version 2.4.2
Version 2.4.3
Version 2.4.4
Version 2.4.5
Version 2.4.6
Version 2.4.7
Version 2.4.8
Version 2.4.9
Version 2.5.0
Version 2.5.1
Version 2.5.2
Version 2.5.3

Related CWEs

Timeline

No history available yet.