← Back

Imap

imap

Vendor: Cyrus • 9 CVEs

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Cyrus
DebianFedoraproject
3Debian Linux
FedoraImap
Nov 21, 2024
Sep 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucke...Show more
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.Show less
2Cyrus
Fedoraproject
2Fedora
Imap
Nov 21, 2024
May 10, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
4Canonical
CyrusDebian+1 more
4Debian Linux
FedoraImap+1 more
Nov 21, 2024
Dec 16, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail acc...Show more
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.Show less
3Cyrus
DebianFedoraproject
3Debian Linux
FedoraImap
Nov 21, 2024
Nov 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connec...Show more
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.Show less
5Canonical
CyrusDebian+2 more
8Debian Linux
Enterprise LinuxEnterprise Linux Eus+5 more
Nov 21, 2024
Jun 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
1Cyrus
1Imap
May 13, 2026
Sep 10, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obt...Show more
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain sensitive information or cause a denial of service (daemon crash) via a 'LIST "" "Other Users"' command.Show less
2Cyrus
Opensuse
3Imap
LeapOpensuse
May 6, 2026
Dec 3, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offs...Show more
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.Show less
2Cyrus
Opensuse
3Imap
LeapOpensuse
May 6, 2026
Dec 3, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet...Show more
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.Show less
2Cyrus
Opensuse
3Imap
LeapOpensuse
May 6, 2026
Dec 3, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vect...Show more
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.Show less