Search CVE reports
1 – 10 of 19 results
CVE-2024-34055
Medium priorityCyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-imapd | Vulnerable | Vulnerable | Ignored | Ignored | — |
cyrus-imapd-2.4 | Not in release | Not in release | Not in release | — | Ignored |
CVE-2021-33582
Medium priorityCyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp...
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-imapd | Not affected | Not affected | Vulnerable | Vulnerable | Ignored |
cyrus-imapd-2.4 | Not in release | Not in release | Not in release | Not in release | Vulnerable |
CVE-2021-32056
Medium priorityCyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
1 affected package
cyrus-imapd
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-imapd | Not affected | Not affected | Not affected | Not affected | Ignored |
CVE-2019-19783
Medium prioritySome fixes available 1 of 3
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on...
1 affected package
cyrus-imapd
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-imapd | — | — | Not affected | Fixed | Not in release |
CVE-2019-18928
Medium prioritySome fixes available 10 of 13
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
1 affected package
cyrus-imapd
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-imapd | Fixed | Fixed | Fixed | Vulnerable | Not in release |
CVE-2019-11356
Medium prioritySome fixes available 4 of 6
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
1 affected package
cyrus-imapd
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-imapd | — | — | Fixed | Fixed | Not in release |
CVE-2017-14230
Medium priorityIn the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain...
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-imapd | — | — | — | Not affected | Not in release |
cyrus-imapd-2.4 | — | — | — | Not in release | Not affected |
CVE-2017-12843
Medium priorityCyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-imapd | — | — | — | — | Not in release |
cyrus-imapd-2.4 | — | — | — | — | Not affected |
CVE-2015-8078
Medium priorityInteger overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the...
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-imapd | Not affected | Not affected | Not affected | Not affected | Not in release |
cyrus-imapd-2.4 | Not in release | Not in release | Not in release | Not in release | Vulnerable |
CVE-2015-8077
Medium priorityInteger overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable....
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cyrus-imapd | Not affected | Not affected | Not affected | Not affected | Not in release |
cyrus-imapd-2.4 | Not in release | Not in release | Not in release | Not in release | Vulnerable |