Search CVE reports


Toggle filters

1 – 10 of 12 results


CVE-2021-38084

Medium priority
Needs evaluation

An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can pipeline commands after the POP3 STLS command, injecting plaintext commands into an encrypted user session.

1 affected package

courier

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
courier Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-28374

Medium priority
Vulnerable

The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information. This may include a cleartext...

1 affected package

courier-authlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
courier-authlib Not affected Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2008-2380

Medium priority
Ignored

SQL injection vulnerability in authpgsqllib.c in Courier-Authlib before 0.62.0, when a non-Latin locale Postgres database is used, allows remote attackers to execute arbitrary SQL commands via query parameters containing apostrophes.

1 affected package

courier-authlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
courier-authlib
Show less packages

CVE-2008-2667

Medium priority
Ignored

SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers...

1 affected package

courier-authlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
courier-authlib
Show less packages

CVE-2006-2659

Unknown priority
Fixed

libs/comverp.c in Courier MTA before 0.53.2 allows attackers to cause a denial of service (CPU consumption) via unknown vectors involving usernames that contain the "=" (equals) character, which is not properly handled during encoding.

1 affected package

courier

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
courier
Show less packages

CVE-2005-3532

Unknown priority
Not affected

authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the...

1 affected package

courier

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
courier
Show less packages

CVE-2005-2820

Unknown priority
Fixed

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" such as "[if]" and "[endif]".

1 affected package

courier

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
courier
Show less packages

CVE-2005-2769

Unknown priority
Fixed

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other...

1 affected package

courier

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
courier
Show less packages

CVE-2005-2724

Unknown priority
Fixed

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature. NOTE: the severity of this issue has been...

1 affected package

courier

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
courier
Show less packages

CVE-2005-2151

Unknown priority
Fixed

spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.

1 affected package

courier

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
courier
Show less packages