3.1
CVE-2026-47088
- EPSS 0.18%
- Veröffentlicht 16.07.2026 00:00:00
- Zuletzt bearbeitet 17.07.2026 18:04:04
- Erkennungen
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory, and read into the heap, returning the read content to the user.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellercyrusimap
≫
Produkt
Cyrus IMAP
Default Statusunaffected
Version
0
Version <
3.12.3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.075 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-126 Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
https://www.cyrusimap.org/imap/download/release-notes/index.html
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html