Search CVE reports


Toggle filters

1 – 10 of 11 results


CVE-2024-34055

Medium priority

Some fixes available 2 of 5

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.

2 affected packages

cyrus-imapd, cyrus-imapd-2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd Not affected Fixed Fixed Ignored Ignored
cyrus-imapd-2.4 Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-33582

Medium priority
Fixed

Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp...

2 affected packages

cyrus-imapd, cyrus-imapd-2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd Not affected Not affected Not affected Fixed Fixed
cyrus-imapd-2.4 Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2017-14230

Medium priority
Ignored

In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain...

2 affected packages

cyrus-imapd, cyrus-imapd-2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd Not affected
cyrus-imapd-2.4 Not in release
Show less packages

CVE-2017-12843

Medium priority
Not affected

Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.

2 affected packages

cyrus-imapd, cyrus-imapd-2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd
cyrus-imapd-2.4
Show less packages

CVE-2015-8078

Medium priority
Ignored

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the...

2 affected packages

cyrus-imapd, cyrus-imapd-2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd Not affected Not affected Not affected Not affected Not affected
cyrus-imapd-2.4 Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2015-8077

Medium priority
Ignored

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. ...

2 affected packages

cyrus-imapd, cyrus-imapd-2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd Not affected Not affected Not affected Not affected Not affected
cyrus-imapd-2.4 Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2015-8076

Medium priority
Ignored

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via...

1 affected package

cyrus-imapd-2.4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd-2.4 Not in release
Show less packages

CVE-2011-3372

Medium priority

Some fixes available 2 of 15

imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.

3 affected packages

cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd-2.2
cyrus-imapd-2.4
kolab-cyrus-imapd
Show less packages

CVE-2011-3481

Low priority

Some fixes available 2 of 18

The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via...

3 affected packages

cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd-2.2
cyrus-imapd-2.4
kolab-cyrus-imapd
Show less packages

CVE-2011-3208

Medium priority

Some fixes available 2 of 15

Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.

3 affected packages

cyrus-imapd-2.2, cyrus-imapd-2.4, kolab-cyrus-imapd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd-2.2
cyrus-imapd-2.4
kolab-cyrus-imapd
Show less packages