Cyrus

Imap

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.4%
  • Veröffentlicht 01.09.2021 06:15:06
  • Zuletzt bearbeitet 21.11.2024 06:09:08

Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This i...

  • EPSS 0.21%
  • Veröffentlicht 10.05.2021 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:06:46

Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.

  • EPSS 1.35%
  • Veröffentlicht 16.12.2019 14:15:12
  • Zuletzt bearbeitet 21.11.2024 04:35:22

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a ...

  • EPSS 0.5%
  • Veröffentlicht 15.11.2019 04:15:10
  • Zuletzt bearbeitet 21.11.2024 04:33:51

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

  • EPSS 28.61%
  • Veröffentlicht 03.06.2019 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:56

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

  • EPSS 0.94%
  • Veröffentlicht 10.09.2017 07:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain sensitive information or c...

  • EPSS 0.81%
  • Veröffentlicht 03.12.2015 20:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulne...

  • EPSS 3.43%
  • Veröffentlicht 03.12.2015 20:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerab...

  • EPSS 2.63%
  • Veröffentlicht 03.12.2015 20:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch ra...