Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Imap CRITICAL 9.1
CVE-2017-14230

In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused…

Fix: after 3.0.3
Fix from $2,300 2017-09-10
Imap HIGH 7.5
CVE-2015-8077

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified i…

Mitigation only
Fix from $1,950 2015-12-03
Imapd HIGH 7.5
CVE-2011-3372

imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO U…

Fix: after 2.4.11
Fix from $1,950 2011-12-24
Imapd MEDIUM 5.1
CVE-2006-2502EPSS 53%

Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute…

No fix yet
Fix from $1,600 2006-05-22
Imapd HIGH 7.5
CVE-2005-0546

Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imapd annotat…

Patch available
Fix from $1,950 2005-05-02
Libsieve HIGH 10.0
CVE-2002-2253EPSS 7%

Multiple buffer overflows in Cyrus Sieve / libSieve 2.1.2 and earlier allow remote attackers to execute arbitrary code via (1) a long header name, (2…

Fix: after 2.1.2
Fix from $1,950 2002-12-31
Sasl HIGH 7.5
CVE-2002-2043

SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary …

Patch available
Fix from $1,950 2002-12-31