4.3

CVE-2014-2014

imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imapsync ProjectImapsync Version <= 1.580
Imapsync ProjectImapsync Version1.53
Imapsync ProjectImapsync Version1.500
Imapsync ProjectImapsync Version1.504
Imapsync ProjectImapsync Version1.508
Imapsync ProjectImapsync Version1.516
Imapsync ProjectImapsync Version1.518
Imapsync ProjectImapsync Version1.525
Imapsync ProjectImapsync Version1.542
Imapsync ProjectImapsync Version1.547
Imapsync ProjectImapsync Version1.554
Imapsync ProjectImapsync Version1.558
Imapsync ProjectImapsync Version1.564
Imapsync ProjectImapsync Version1.567
Imapsync ProjectImapsync Version1.569
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.549
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.