Show filters
79 Total Results
Displaying 11-20 of 79
Sort by:
Attacker Value
Unknown
CVE-2021-33582
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.
0
Attacker Value
Unknown
CVE-2021-32056
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
0
Attacker Value
Unknown
CVE-2020-13163
Disclosure Date: May 19, 2020 (last updated February 21, 2025)
em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
0
Attacker Value
Unknown
CVE-2019-19783
Disclosure Date: December 16, 2019 (last updated November 08, 2023)
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.
0
Attacker Value
Unknown
CVE-2019-18928
Disclosure Date: November 15, 2019 (last updated November 08, 2023)
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
0
Attacker Value
Unknown
CVE-2010-4533
Disclosure Date: November 13, 2019 (last updated November 27, 2024)
offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.
0
Attacker Value
Unknown
CVE-2010-4532
Disclosure Date: November 13, 2019 (last updated November 27, 2024)
offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.
0
Attacker Value
Unknown
CVE-2016-10937
Disclosure Date: September 08, 2019 (last updated November 08, 2023)
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
0
Attacker Value
Unknown
CVE-2019-11356
Disclosure Date: June 03, 2019 (last updated November 08, 2023)
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
0
Attacker Value
Unknown
CVE-2018-0687
Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0