Isync Project
isync_project
4 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectIsync Project+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Feb 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause...Show more |
3Debian FedoraprojectIsync Project3Debian Linux FedoraIsyncNov 21, 2024 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an u...Show more |
3Debian FedoraprojectIsync Project3Debian Linux FedoraIsyncNov 21, 2024 Nov 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line...Show more |
Isync 0.4 before 1.0.6, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof...Show more |