Show filters
22 Total Results
Displaying 21-22 of 22
Sort by:
Attacker Value
Unknown

CVE-2002-2043

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.
0
Attacker Value
Unknown

CVE-2002-1347

Disclosure Date: December 18, 2002 (last updated February 22, 2025)
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.