Search CVE reports
21 – 30 of 35 results
Some fixes available 11 of 13
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
1 affected package
cyrus-imapd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd | — | Fixed | Fixed | Fixed | Fixed |
Some fixes available 4 of 6
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
1 affected package
cyrus-imapd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd | — | — | — | Fixed | Fixed |
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain...
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd | — | — | — | — | Not affected |
| cyrus-imapd-2.4 | — | — | — | — | Not in release |
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd | — | — | — | — | — |
| cyrus-imapd-2.4 | — | — | — | — | — |
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the...
2 affected packages
cyrus-imapd-2.4, cyrus-imapd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd-2.4 | Not in release | Not in release | Not in release | Not in release | Not in release |
| cyrus-imapd | Not affected | Not affected | Not affected | Not affected | Not affected |
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. ...
2 affected packages
cyrus-imapd-2.4, cyrus-imapd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd-2.4 | Not in release | Not in release | Not in release | Not in release | Not in release |
| cyrus-imapd | Not affected | Not affected | Not affected | Not affected | Not affected |
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via...
1 affected package
cyrus-imapd-2.4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd-2.4 | — | — | — | — | Not in release |
Some fixes available 2 of 15
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
3 affected packages
cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd-2.2 | — | — | — | — | — |
| cyrus-imapd-2.4 | — | — | — | — | — |
| kolab-cyrus-imapd | — | — | — | — | — |
Some fixes available 2 of 18
The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via...
3 affected packages
cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd-2.2 | — | — | — | — | — |
| cyrus-imapd-2.4 | — | — | — | — | — |
| kolab-cyrus-imapd | — | — | — | — | — |
Some fixes available 2 of 15
Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.
3 affected packages
cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cyrus-imapd-2.2 | — | — | — | — | — |
| cyrus-imapd-2.4 | — | — | — | — | — |
| kolab-cyrus-imapd | — | — | — | — | — |