Search CVE reports


Toggle filters

21 – 30 of 35 results


CVE-2019-18928

Medium priority

Some fixes available 11 of 13

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

1 affected package

cyrus-imapd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-11356

Medium priority

Some fixes available 4 of 6

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

1 affected package

cyrus-imapd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd Fixed Fixed
Show less packages

CVE-2017-14230

Medium priority
Ignored

In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain...

2 affected packages

cyrus-imapd, cyrus-imapd-2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd Not affected
cyrus-imapd-2.4 Not in release
Show less packages

CVE-2017-12843

Medium priority
Not affected

Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.

2 affected packages

cyrus-imapd, cyrus-imapd-2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd
cyrus-imapd-2.4
Show less packages

CVE-2015-8078

Medium priority
Vulnerable

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the...

2 affected packages

cyrus-imapd-2.4, cyrus-imapd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd-2.4 Not in release Not in release Not in release Not in release Not in release
cyrus-imapd Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2015-8077

Medium priority
Vulnerable

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. ...

2 affected packages

cyrus-imapd-2.4, cyrus-imapd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd-2.4 Not in release Not in release Not in release Not in release Not in release
cyrus-imapd Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2015-8076

Medium priority
Ignored

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via...

1 affected package

cyrus-imapd-2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd-2.4 Not in release
Show less packages

CVE-2011-3372

Medium priority

Some fixes available 2 of 15

imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.

3 affected packages

cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd-2.2
cyrus-imapd-2.4
kolab-cyrus-imapd
Show less packages

CVE-2011-3481

Low priority

Some fixes available 2 of 18

The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via...

3 affected packages

cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd-2.2
cyrus-imapd-2.4
kolab-cyrus-imapd
Show less packages

CVE-2011-3208

Medium priority

Some fixes available 2 of 15

Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.

3 affected packages

cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd-2.2
cyrus-imapd-2.4
kolab-cyrus-imapd
Show less packages