Vulnerabilities > Cyrusimap > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-05 CVE-2024-34055 Allocation of Resources Without Limits or Throttling vulnerability in Cyrusimap Cyrus Imap
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
network
low complexity
cyrusimap CWE-770
6.5
2017-08-22 CVE-2017-12843 Improper Input Validation vulnerability in multiple products
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
network
low complexity
cyrusimap fedoraproject CWE-20
6.5