7.5

CVE-2015-8078

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.

Data is provided by the National Vulnerability Database (NVD)
OpensuseLeap Version42.1
OpensuseOpensuse Version13.2
CyrusImap Version2.3.0
CyrusImap Version2.3.1
CyrusImap Version2.3.2
CyrusImap Version2.3.3
CyrusImap Version2.3.4
CyrusImap Version2.3.5
CyrusImap Version2.3.6
CyrusImap Version2.3.7
CyrusImap Version2.3.8
CyrusImap Version2.3.9
CyrusImap Version2.3.10
CyrusImap Version2.3.11
CyrusImap Version2.3.12
CyrusImap Version2.3.13
CyrusImap Version2.3.14
CyrusImap Version2.3.15
CyrusImap Version2.3.16
CyrusImap Version2.3.17
CyrusImap Version2.3.18
CyrusImap Version2.4.0
CyrusImap Version2.4.1
CyrusImap Version2.4.2
CyrusImap Version2.4.3
CyrusImap Version2.4.4
CyrusImap Version2.4.5
CyrusImap Version2.4.6
CyrusImap Version2.4.7
CyrusImap Version2.4.8
CyrusImap Version2.4.9
CyrusImap Version2.4.10
CyrusImap Version2.4.11
CyrusImap Version2.4.12
CyrusImap Version2.4.13
CyrusImap Version2.4.14
CyrusImap Version2.4.15
CyrusImap Version2.4.16
CyrusImap Version2.4.17
CyrusImap Version2.5.0
CyrusImap Version2.5.1
CyrusImap Version2.5.2
CyrusImap Version2.5.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.81% 0.733
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P