Vulnerabilities > Cyrus

DATE CVE VULNERABILITY TITLE RISK
2021-09-01 CVE-2021-33582 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Cyrus Imap
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction.
network
low complexity
cyrus CWE-327
5.0
2021-05-10 CVE-2021-32056 Incorrect Permission Assignment for Critical Resource vulnerability in Cyrus Imap
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
network
low complexity
cyrus CWE-732
4.0
2019-12-16 CVE-2019-19783 Improper Input Validation vulnerability in multiple products
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8.
network
cyrus debian CWE-20
3.5
2019-11-15 CVE-2019-18928 Unspecified vulnerability in Cyrus Imap
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
network
low complexity
cyrus
7.5
2019-06-03 CVE-2019-11356 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cyrus Imap
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
network
low complexity
cyrus CWE-119
7.5
2017-09-10 CVE-2017-14230 Improper Input Validation vulnerability in Cyrus Imap
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain sensitive information or cause a denial of service (daemon crash) via a 'LIST "" "Other Users"' command.
network
low complexity
cyrus CWE-20
6.4
2015-12-03 CVE-2015-8078 Numeric Errors vulnerability in multiple products
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable.
network
low complexity
opensuse cyrus CWE-189
7.5
2015-12-03 CVE-2015-8077 Numeric Errors vulnerability in multiple products
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable.
network
low complexity
cyrus opensuse CWE-189
7.5
2015-12-03 CVE-2015-8076 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.
network
low complexity
opensuse cyrus CWE-119
7.5
2011-12-24 CVE-2011-3372 Improper Authentication vulnerability in Cyrus Imapd
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
network
low complexity
cyrus CWE-287
7.5