5
CVSSv2

CVE-2014-0079

Published: 28/04/2014 Updated: 29/04/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and previous versions, when using certain build conditions, allows remote malicious users to cause a denial of service (crash) via vectors related to "a NULL pointer of the password."

Vulnerable Product Search on Vulmon Subscribe to Product

zarafa zarafa 6.03

zarafa zarafa 6.11

zarafa zarafa 5.10

zarafa zarafa 5.02

zarafa zarafa 5.11

zarafa zarafa 5.20

zarafa zarafa 5.22

zarafa zarafa 6.00

zarafa zarafa 6.02

zarafa zarafa 5.00

zarafa zarafa 7.1.8

zarafa zarafa 6.01

zarafa zarafa 6.10

zarafa zarafa 5.01

zarafa zarafa