Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cyrus imapd vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2019-18928
Cyrus IMAP 2.5.x prior to 2.5.14 and 3.x prior to 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
Cyrus Imap
Fedoraproject Fedora 30
Fedoraproject Fedora 31
Debian Debian Linux 9.0
9.8
CVSSv3
CVE-2019-11356
The CalDAV feature in httpd in Cyrus IMAP 2.5.x up to and including 2.5.12 and 3.0.x up to and including 3.0.9 allows remote malicious users to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
Cyrus Imap
Fedoraproject Fedora 29
Fedoraproject Fedora 30
Debian Debian Linux 9.0
Canonical Ubuntu Linux 18.04
Redhat Enterprise Linux 8.0
Redhat Enterprise Linux Eus 8.1
Redhat Enterprise Linux Eus 8.2
Redhat Enterprise Linux Server Tus 8.2
Redhat Enterprise Linux Server Aus 8.2
Redhat Enterprise Linux Server Tus 8.4
Redhat Enterprise Linux Eus 8.4
Redhat Enterprise Linux Server Aus 8.4
7.5
CVSSv3
CVE-2021-33582
Cyrus IMAP prior to 3.4.2 allows remote malicious users to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2....
Cyrus Imap
Fedoraproject Fedora 34
Fedoraproject Fedora 35
Debian Debian Linux 9.0
6.5
CVSSv3
CVE-2019-19783
An issue exists in Cyrus IMAP prior to 2.5.15, 3.0.x prior to 3.0.13, and 3.1.x up to and including 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containin...
Cyrus Imap
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Fedoraproject Fedora 30
Fedoraproject Fedora 31
Canonical Ubuntu Linux 18.04
NA
CVE-2015-8076
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x prior to 2.3.19, 2.4.x prior to 2.4.18, 2.5.x prior to 2.5.4 allows remote malicious users to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which trigger...
Opensuse Opensuse 13.2
Opensuse Leap 42.1
Cyrus Imap 2.3.0
Cyrus Imap 2.3.1
Cyrus Imap 2.3.8
Cyrus Imap 2.3.9
Cyrus Imap 2.3.16
Cyrus Imap 2.3.17
Cyrus Imap 2.4.6
Cyrus Imap 2.4.7
Cyrus Imap 2.4.14
Cyrus Imap 2.4.15
Cyrus Imap 2.3.6
Cyrus Imap 2.3.7
Cyrus Imap 2.3.14
Cyrus Imap 2.3.15
Cyrus Imap 2.4.4
Cyrus Imap 2.4.5
Cyrus Imap 2.4.12
Cyrus Imap 2.4.13
Cyrus Imap 2.5.2
Cyrus Imap 2.5.3
NA
CVE-2015-8077
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote malicious users to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerability exists because of a...
Cyrus Imap 2.4.4
Cyrus Imap 2.3.7
Cyrus Imap 2.4.6
Cyrus Imap 2.3.4
Cyrus Imap 2.4.16
Cyrus Imap 2.4.1
Cyrus Imap 2.3.5
Cyrus Imap 2.3.17
Cyrus Imap 2.4.0
Cyrus Imap 2.4.11
Cyrus Imap 2.5.1
Cyrus Imap 2.4.8
Cyrus Imap 2.4.10
Cyrus Imap 2.3.3
Cyrus Imap 2.3.8
Cyrus Imap 2.4.2
Cyrus Imap 2.5.0
Cyrus Imap 2.4.14
Cyrus Imap 2.3.14
Cyrus Imap 2.3.1
Cyrus Imap 2.4.17
Cyrus Imap 2.3.13
NA
CVE-2015-8078
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote malicious users to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulnerability exists because o...
Opensuse Leap 42.1
Opensuse Opensuse 13.2
Cyrus Imap 2.4.4
Cyrus Imap 2.3.7
Cyrus Imap 2.4.6
Cyrus Imap 2.3.4
Cyrus Imap 2.4.16
Cyrus Imap 2.4.1
Cyrus Imap 2.3.5
Cyrus Imap 2.3.17
Cyrus Imap 2.4.0
Cyrus Imap 2.4.11
Cyrus Imap 2.5.1
Cyrus Imap 2.4.8
Cyrus Imap 2.4.10
Cyrus Imap 2.3.3
Cyrus Imap 2.3.8
Cyrus Imap 2.4.2
Cyrus Imap 2.5.0
Cyrus Imap 2.4.14
Cyrus Imap 2.3.14
Cyrus Imap 2.3.1
NA
CVE-2011-3372
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x prior to 2.4.12 allows remote malicious users to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.
Cyrus Imapd
NA
CVE-2011-3208
Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server prior to 2.3.17 and 2.4.x prior to 2.4.11 allows remote malicious users to execute arbitrary code via a crafted NNTP command.
Cmu Cyrus Imap Server 2.0.17
Cmu Cyrus Imap Server 2.1.16
Cmu Cyrus Imap Server 2.2.11
Cmu Cyrus Imap Server 2.2.9
Cmu Cyrus Imap Server 2.3.1
Cmu Cyrus Imap Server 2.3.0
Cmu Cyrus Imap Server 2.3.11
Cmu Cyrus Imap Server 2.1.17
Cmu Cyrus Imap Server 2.1.18
Cmu Cyrus Imap Server 2.2.10
Cmu Cyrus Imap Server 2.2.8
Cmu Cyrus Imap Server 2.3.15
Cmu Cyrus Imap Server 2.3.13
Cmu Cyrus Imap Server 2.3.9
Cmu Cyrus Imap Server 2.3.10
Cmu Cyrus Imap Server 2.3.14
Cmu Cyrus Imap Server 2.2.14
Cmu Cyrus Imap Server 2.2.12
Cmu Cyrus Imap Server 2.3.4
Cmu Cyrus Imap Server 2.3.12
Cmu Cyrus Imap Server 2.3.7
Cmu Cyrus Imap Server 2.3.8
NA
CVE-2011-3481
The index_get_ids function in index.c in imapd in Cyrus IMAP Server prior to 2.4.11, when server-side threading is enabled, allows remote malicious users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.
Cmu Cyrus Imap Server 2.3.13
Cmu Cyrus Imap Server 2.3.9
Cmu Cyrus Imap Server 2.3.7
Cmu Cyrus Imap Server 2.3.8
Cmu Cyrus Imap Server 2.4.8
Cmu Cyrus Imap Server 2.0.17
Cmu Cyrus Imap Server 2.2.9
Cmu Cyrus Imap Server 2.2.8
Cmu Cyrus Imap Server
Cmu Cyrus Imap Server 2.3.17
Cmu Cyrus Imap Server 2.3.15
Cmu Cyrus Imap Server 2.3.2
Cmu Cyrus Imap Server 2.4.9
Cmu Cyrus Imap Server 2.4.0
Cmu Cyrus Imap Server 2.1.16
Cmu Cyrus Imap Server 2.4.7
Cmu Cyrus Imap Server 2.3.1
Cmu Cyrus Imap Server 2.3.0
Cmu Cyrus Imap Server 2.3.14
Cmu Cyrus Imap Server 2.3.16
Cmu Cyrus Imap Server 2.3.12
Cmu Cyrus Imap Server 2.3.5
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »