CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Cyrus DebianFedoraproject3Debian Linux FedoraImapNov 21, 2024 Sep 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucke...Show more |
2Cyrus Fedoraproject2Fedora ImapNov 21, 2024 May 10, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall. |
4Canonical CyrusDebian+1 more4Debian Linux FedoraImap+1 moreNov 21, 2024 Dec 16, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail acc...Show more |
3Cyrus DebianFedoraproject3Debian Linux FedoraImapNov 21, 2024 Nov 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connec...Show more |
5Canonical CyrusDebian+2 more8Debian Linux Enterprise LinuxEnterprise Linux Eus+5 moreNov 21, 2024 Jun 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name. |
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obt...Show more |
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offs...Show more |
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet...Show more |
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vect...Show more |