cyrusimap CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

cyrusimap vulnerability overview

Aggregates CVE and security vulnerability intelligence across all cyrusimap-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk sql injection, vendor risk buffer overflow, and vendor risk memory corruption; exposure may include vendor impact memory corruption in vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-34055 Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command. [email protected] 6.5 0.29% 2024-06-05 2024-12-06
CVE-2022-24407 In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. [email protected] 8.8 0.43% 2022-02-24 2024-11-21
CVE-2019-19906 cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl. [email protected] 7.5 0.48% 2019-12-19 2024-11-21
CVE-2017-12843 Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command. [email protected] 6.5 0.23% 2017-08-22 2026-05-13
CVE-2002-1347 Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string. [email protected] 9.8 9.98% 2002-12-18 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence