Cyrus IMAP 2.4.16

CPE Details

Cyrus IMAP 2.4.16
2.4.16
2015-12-04
13h24 +00:00
2015-12-04
13h24 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:cyrus:imap:2.4.16:*:*:*:*:*:*:*

Informations

Vendor

cyrus

Product

imap

Version

2.4.16

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-33582 2021-09-01 03h32 +00:00 Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.
7.5
High
CVE-2021-32056 2021-05-10 11h05 +00:00 Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
4.3
Medium
CVE-2017-14230 2017-09-10 07h00 +00:00 In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain sensitive information or cause a denial of service (daemon crash) via a 'LIST "" "Other Users"' command.
9.1
Critical
CVE-2015-8076 2015-12-03 19h00 +00:00 The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.
7.5
CVE-2015-8077 2015-12-03 19h00 +00:00 Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
7.5
CVE-2015-8078 2015-12-03 19h00 +00:00 Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.
7.5