Show filters
79 Total Results
Displaying 41-50 of 79
Sort by:
Attacker Value
Unknown
CVE-2009-1381
Disclosure Date: May 22, 2009 (last updated November 08, 2023)
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue exists because of an incomplete fix for CVE-2009-1579.
0
Attacker Value
Unknown
CVE-2008-5514
Disclosure Date: December 23, 2008 (last updated October 04, 2023)
Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-2007e and other applications, allows context-dependent attackers to cause a denial of service (crash) via an e-mail message that triggers a buffer overflow.
0
Attacker Value
Unknown
CVE-2008-5005
Disclosure Date: November 10, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in (1) University of Washington IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine 2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain privileges by specifying a long folder extension argument on the command line to the tmail or dmail program; and (b) remote attackers to execute arbitrary code by sending e-mail to a destination mailbox name composed of a username and '+' character followed by a long string, processed by the tmail or possibly dmail program.
0
Attacker Value
Unknown
CVE-2008-5006
Disclosure Date: November 10, 2008 (last updated October 04, 2023)
smtp.c in the c-client library in University of Washington IMAP Toolkit 2007b allows remote SMTP servers to cause a denial of service (NULL pointer dereference and application crash) by responding to the QUIT command with a close of the TCP connection instead of the expected 221 response code.
0
Attacker Value
Unknown
CVE-2007-2173
Disclosure Date: April 24, 2007 (last updated October 04, 2023)
Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.
0
Attacker Value
Unknown
CVE-2007-1578
Disclosure Date: March 21, 2007 (last updated October 04, 2023)
Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow.
0
Attacker Value
Unknown
CVE-2007-1579
Disclosure Date: March 21, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command.
0
Attacker Value
Unknown
CVE-2006-2502
Disclosure Date: May 22, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
0
Attacker Value
Unknown
CVE-2005-3189
Disclosure Date: November 18, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in Qualcomm WorldMail IMAP Server allows remote attackers to read arbitrary email messages via ".." sequences in the SELECT command.
0
Attacker Value
Unknown
CVE-2005-2661
Disclosure Date: October 14, 2005 (last updated February 22, 2025)
Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows remote IMAP servers to execute arbitrary code via format string specifiers in a banner or capability line.
0