Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown
CVE-2024-34055
Disclosure Date: June 05, 2024 (last updated June 12, 2024)
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
0
Attacker Value
Unknown
CVE-2022-24407
Disclosure Date: February 24, 2022 (last updated November 08, 2023)
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
0
Attacker Value
Unknown
CVE-2021-33582
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.
0
Attacker Value
Unknown
CVE-2021-32056
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
0
Attacker Value
Unknown
CVE-2019-19906
Disclosure Date: December 19, 2019 (last updated November 08, 2023)
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
0
Attacker Value
Unknown
CVE-2019-19783
Disclosure Date: December 16, 2019 (last updated November 08, 2023)
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.
0
Attacker Value
Unknown
CVE-2019-18928
Disclosure Date: November 15, 2019 (last updated November 08, 2023)
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
0
Attacker Value
Unknown
CVE-2019-11356
Disclosure Date: June 03, 2019 (last updated November 08, 2023)
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
0
Attacker Value
Unknown
CVE-2017-14230
Disclosure Date: September 10, 2017 (last updated November 26, 2024)
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain sensitive information or cause a denial of service (daemon crash) via a 'LIST "" "Other Users"' command.
0
Attacker Value
Unknown
CVE-2017-12843
Disclosure Date: August 22, 2017 (last updated November 08, 2023)
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
0