Vulnerabilities
Vulnerable Software
Cyrus:  >> Imap  >> 2.0.4  Security Vulnerabilities
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.
CVSS Score
7.5
EPSS Score
0.009
Published
2021-09-01
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
CVSS Score
4.3
EPSS Score
0.003
Published
2021-05-10
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain sensitive information or cause a denial of service (daemon crash) via a 'LIST "" "Other Users"' command.
CVSS Score
9.1
EPSS Score
0.009
Published
2017-09-10


Contact Us

Shodan ® - All rights reserved