Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown
CVE-2015-8076
Disclosure Date: December 03, 2015 (last updated October 05, 2023)
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.
0
Attacker Value
Unknown
CVE-2015-8077
Disclosure Date: December 03, 2015 (last updated November 08, 2023)
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
0
Attacker Value
Unknown
CVE-2015-8078
Disclosure Date: December 03, 2015 (last updated November 08, 2023)
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
0
Attacker Value
Unknown
CVE-2011-3372
Disclosure Date: December 24, 2011 (last updated October 04, 2023)
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
0
Attacker Value
Unknown
CVE-2006-2502
Disclosure Date: May 22, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
0
Attacker Value
Unknown
CVE-2006-1721
Disclosure Date: April 11, 2006 (last updated October 04, 2023)
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.
0
Attacker Value
Unknown
CVE-2005-0546
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imapd annotate extension, (2) an off-by-one error in "cached header handling," (3) a stack-based buffer overflow in fetchnews, or (4) a stack-based buffer overflow in imapd.
0
Attacker Value
Unknown
CVE-2004-0884
Disclosure Date: January 27, 2005 (last updated February 22, 2025)
The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.
0
Attacker Value
Unknown
CVE-2005-0373
Disclosure Date: October 07, 2004 (last updated February 22, 2025)
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2002-2253
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Multiple buffer overflows in Cyrus Sieve / libSieve 2.1.2 and earlier allow remote attackers to execute arbitrary code via (1) a long header name, (2) a long IMAP flag, or (3) a script that generates a large number of errors that overflow the resulting error string.
0