Cyrusimap

Cyrus Imap

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 16.07.2026 00:00:00
  • Zuletzt bearbeitet 17.07.2026 18:04:04

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge ...

  • EPSS 0.21%
  • Veröffentlicht 16.07.2026 00:00:00
  • Zuletzt bearbeitet 17.07.2026 18:04:04

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for which they had no perm...

  • EPSS 0.19%
  • Veröffentlicht 16.07.2026 00:00:00
  • Zuletzt bearbeitet 17.07.2026 18:04:04

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would ...

  • EPSS 0.2%
  • Veröffentlicht 16.07.2026 00:00:00
  • Zuletzt bearbeitet 17.07.2026 18:04:04

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script used :fcc (to save a copy of the sent message) could deliver vacation auto-reply cop...

  • EPSS 0.16%
  • Veröffentlicht 16.07.2026 00:00:00
  • Zuletzt bearbeitet 17.07.2026 18:04:04

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via t...

  • EPSS 0.84%
  • Veröffentlicht 05.06.2024 05:15:49
  • Zuletzt bearbeitet 06.12.2024 15:15:08

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.

  • EPSS 1.23%
  • Veröffentlicht 22.08.2017 14:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.