CVE-2026-61908
- EPSS 0.21%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:24:33
An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the en...
CVE-2026-61909
- EPSS 0.2%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:24:24
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by includin...
- EPSS 0.19%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:24:04
An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This c...
CVE-2026-61911
- EPSS 0.22%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:23:58
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotat...
CVE-2026-61915
- EPSS 0.22%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 15:23:51
An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more proper...
CVE-2021-33582
- EPSS 3.07%
- Veröffentlicht 01.09.2021 06:15:06
- Zuletzt bearbeitet 21.11.2024 06:09:08
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This i...
CVE-2021-32056
- EPSS 1.7%
- Veröffentlicht 10.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:46
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
CVE-2019-19783
- EPSS 1.66%
- Veröffentlicht 16.12.2019 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:22
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a ...
CVE-2019-18928
- EPSS 2.39%
- Veröffentlicht 15.11.2019 04:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:51
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
CVE-2019-11356
- EPSS 7.62%
- Veröffentlicht 03.06.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:56
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.