Cyrus Imap vulnerabilities

9 known vulnerabilities affecting cyrus/imap.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2021-33582HIGHCVSS 7.5fixed in 3.0.16≥ 3.2.0, < 3.2.8+1 more2021-09-01
CVE-2021-33582 [HIGH] CWE-407 CVE-2021-33582: Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.
nvd
CVE-2021-32056MEDIUMCVSS 4.3fixed in 3.2.7≥ 3.3.0, < 3.4.12021-05-10
CVE-2021-32056 [MEDIUM] CWE-732 CVE-2021-32056: Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypa Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
nvd
CVE-2019-19783MEDIUMCVSS 6.5≥ 2.5.0, < 2.5.15≥ 3.0.0, < 3.0.13+1 more2019-12-16
CVE-2019-19783 [MEDIUM] CWE-269 CVE-2019-19783: An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. I An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, bec
nvd
CVE-2019-18928CRITICALCVSS 9.8≥ 2.5.0, < 2.5.14≥ 3.0.0, < 3.0.122019-11-15
CVE-2019-18928 [CRITICAL] CVE-2019-18928: Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP req Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
nvd
CVE-2019-11356CRITICALCVSS 9.8≥ 2.5.0, ≤ 2.5.12≥ 3.0.0, ≤ 3.0.92019-06-03
CVE-2019-11356 [CRITICAL] CWE-787 CVE-2019-11356: The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
nvd
CVE-2017-14230CRITICALCVSS 9.1≤ 3.0.32017-09-10
CVE-2017-14230 [CRITICAL] CWE-20 CVE-2017-14230: In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain sensitive information or cause a denial of service (daemon crash) via a 'LIST "" "Other Users"' command.
nvd
CVE-2015-8078HIGHCVSS 7.5v2.3.0v2.3.1+39 more2015-12-03
CVE-2015-8078 [HIGH] CVE-2015-8078: Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2. Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
nvd
CVE-2015-8077HIGHCVSS 7.5v2.3.0v2.3.1+39 more2015-12-03
CVE-2015-8077 [HIGH] CVE-2015-8077: Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2. Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
nvd
CVE-2015-8076HIGHCVSS 7.5v2.3.0v2.3.1+39 more2015-12-03
CVE-2015-8076 [HIGH] CWE-119 CVE-2015-8076: The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.
nvd