Show filters
79 Total Results
Displaying 21-30 of 79
Sort by:
Attacker Value
Unknown
CVE-2018-0683
Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via Cookie data.
0
Attacker Value
Unknown
CVE-2018-0682
Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not properly manage sessions, which allows remote attackers to read/send mail or change the configuration via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-0684
Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via multipart/form-data format data.
0
Attacker Value
Unknown
CVE-2018-0680
Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to read/send mail or change the configuration.
0
Attacker Value
Unknown
CVE-2018-0681
Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to login to the Management page and change the configuration.
0
Attacker Value
Unknown
CVE-2018-0686
Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote authenticated attackers to upload and execute any executable files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-14230
Disclosure Date: September 10, 2017 (last updated November 26, 2024)
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain sensitive information or cause a denial of service (daemon crash) via a 'LIST "" "Other Users"' command.
0
Attacker Value
Unknown
CVE-2017-12843
Disclosure Date: August 22, 2017 (last updated November 08, 2023)
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
0
Attacker Value
Unknown
CVE-2015-8076
Disclosure Date: December 03, 2015 (last updated October 05, 2023)
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.
0
Attacker Value
Unknown
CVE-2015-8077
Disclosure Date: December 03, 2015 (last updated November 08, 2023)
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
0