Search CVE reports
1 – 10 of 20 results
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.
1 affected package
cyrus-imapd
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cyrus-imapd | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 2 of 6
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cyrus-imapd | Fixed | Fixed | Ignored | Ignored |
cyrus-imapd-2.4 | Not in release | Not in release | Not in release | — |
Some fixes available 2 of 3
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp...
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cyrus-imapd | Not affected | Not affected | Fixed | Fixed |
cyrus-imapd-2.4 | Not in release | Not in release | Not in release | Not in release |
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
1 affected package
cyrus-imapd
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cyrus-imapd | Not affected | Not affected | Not affected | Not affected |
Some fixes available 1 of 3
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on...
1 affected package
cyrus-imapd
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cyrus-imapd | — | — | Not affected | Fixed |
Some fixes available 11 of 13
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
1 affected package
cyrus-imapd
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cyrus-imapd | Fixed | Fixed | Fixed | Fixed |
Some fixes available 4 of 6
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
1 affected package
cyrus-imapd
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cyrus-imapd | — | — | Fixed | Fixed |
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain...
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cyrus-imapd | — | — | — | Not affected |
cyrus-imapd-2.4 | — | — | — | Not in release |
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
2 affected packages
cyrus-imapd, cyrus-imapd-2.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cyrus-imapd | — | — | — | — |
cyrus-imapd-2.4 | — | — | — | — |
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the...
2 affected packages
cyrus-imapd-2.4, cyrus-imapd
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cyrus-imapd-2.4 | Not in release | Not in release | Not in release | Not in release |
cyrus-imapd | Not affected | Not affected | Not affected | Not affected |