Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cyrus sasl 2.1.18 r1 vulnerabilities and exploits
(subscribe to this query)
2.6
CVSSv2
CVE-2006-1721
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions prior to 2.1.21, allows remote unauthenticated malicious users to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation...
Cyrus Sasl 2.1.18 R1
Cyrus Sasl 2.1.19
Cyrus Sasl 2.1.18
Cyrus Sasl 2.1.18 R2
Cyrus Sasl 2.1.20
7.2
CVSSv2
CVE-2004-0884
The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and previous versions trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users to execute arbitrary code by modifying the SASL_PATH to point to malicious programs.
Cyrus Sasl 2.1.16
Cyrus Sasl 2.1.13
Conectiva Linux 9.0
Cyrus Sasl 2.1.18 R1
Cyrus Sasl 2.1.11
Cyrus Sasl 1.5.24
Cyrus Sasl 1.5.27
Cyrus Sasl 2.1.14
Cyrus Sasl 1.5.28
Cyrus Sasl 2.1.18
Cyrus Sasl 2.1.12
Cyrus Sasl 2.1.17
Conectiva Linux 10.0
Cyrus Sasl 2.1.9
Cyrus Sasl 2.1.10
Cyrus Sasl 2.1.15
7.5
CVSSv2
CVE-2005-0373
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote malicious users to execute arbitrary code.
Cyrus Sasl 2.1.16
Cyrus Sasl 2.1.13
Conectiva Linux 9.0
Cyrus Sasl 2.1.18 R1
Cyrus Sasl 2.1.11
Openpkg Openpkg 2.1
Cyrus Sasl 1.5.24
Cyrus Sasl 1.5.27
Cyrus Sasl 2.1.14
Cyrus Sasl 1.5.28
Cyrus Sasl 2.1.18
Cyrus Sasl 2.1.12
Cyrus Sasl 2.1.17
Openpkg Openpkg 2.2
Suse Suse Cvsup 16.1h 36.i586
Conectiva Linux 10.0
Cyrus Sasl 2.1.9
Cyrus Sasl 2.1.10
Cyrus Sasl 2.1.15
Suse Suse Linux 9.0
Apple Mac Os X Server 10.3.2
Apple Mac Os X Server 10.1.5
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-6267
XML injection
CVE-2024-37673
CVE-2024-6266
CVE-2024-30078
arbitrary
CVE-2024-36886
CVE-2024-5346
template injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started