Show filters
79 Total Results
Displaying 31-40 of 79
Sort by:
Attacker Value
Unknown

CVE-2015-8078

Disclosure Date: December 03, 2015 (last updated November 08, 2023)
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
0
Attacker Value
Unknown

CVE-2013-4279

Disclosure Date: April 18, 2014 (last updated October 05, 2023)
imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating system, and Perl version) to the developer's site.
0
Attacker Value
Unknown

CVE-2014-2014

Disclosure Date: April 18, 2014 (last updated October 05, 2023)
imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.
0
Attacker Value
Unknown

CVE-2011-3372

Disclosure Date: December 24, 2011 (last updated October 04, 2023)
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
0
Attacker Value
Unknown

CVE-2011-3208

Disclosure Date: September 14, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.
0
Attacker Value
Unknown

CVE-2011-3481

Disclosure Date: September 14, 2011 (last updated October 04, 2023)
The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.
0
Attacker Value
Unknown

CVE-2011-1926

Disclosure Date: May 23, 2011 (last updated October 04, 2023)
The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
0
Attacker Value
Unknown

CVE-2010-1953

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown

CVE-2009-2632

Disclosure Date: September 08, 2009 (last updated October 04, 2023)
Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
0
Attacker Value
Unknown

CVE-2008-7022

Disclosure Date: August 21, 2009 (last updated October 04, 2023)
Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote attackers to execute arbitrary programs via the LoadXmlEmail method.
0