Записи cyrus
22 опубликованных записей вендора cyrus.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 4,5 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 81,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-189 Numeric Errors2
- CWE-20 Improper Input Validation2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-287 Improper Authentication1
- CWE-407 Inefficient Algorithmic Complexity1
- CWE-415 Double Free1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2002-2253Эксплойта нет | Multiple buffer overflows in Cyrus Sieve / libSieve 2.1.2 and earlier allow remote attackers to execute arbitrary code via (1) a long headercyrus · libsieve · CWE-119 | Критическая10,0 | — | 6,6 % | 31 дек. 2002 г. |
41В плане | CVE-2019-11356Эксплойта нет | The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code viacyrus · imap · CWE-787 | Критическая9,8 | — | 7,6 % | 3 июн. 2019 г. |
40В плане | CVE-2019-18928Эксплойта нет | Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authenticcyrus · imap | Критическая9,8 | — | 2,4 % | 15 нояб. 2019 г. |
37Наблюдать | CVE-2017-14230Эксплойта нет | In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST commacyrus · imap · CWE-20 | Критическая9,1 | — | 2,2 % | 10 сент. 2017 г. |
36Наблюдать | CVE-2006-2502Готовый эксплойт | Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers tcyrus · imapd | Средняя5,1 | — | 53,3 % | 22 мая 2006 г. |
31Наблюдать | CVE-2005-0546Эксплойта нет | Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imapcyrus · imapd | Высокая7,5 | — | 4,2 % | 2 мая 2005 г. |
31Наблюдать | CVE-2005-0373Эксплойта нет | Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bucyrus · sasl | Высокая7,5 | — | 3,9 % | 7 окт. 2004 г. |
31Наблюдать | CVE-2011-3372Эксплойта нет | imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an Acyrus · imapd · CWE-287 | Высокая7,5 | — | 3,3 % | 24 дек. 2011 г. |
31Наблюдать | CVE-2015-8076Эксплойта нет | The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers tocyrus · imap · CWE-119 | Высокая7,5 | — | 3,3 % | 3 дек. 2015 г. |
31Наблюдать | CVE-2015-8077Эксплойта нет | Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspcyrus · imap · CWE-189 | Высокая7,5 | — | 3,3 % | 3 дек. 2015 г. |
31Наблюдать | CVE-2021-33582Эксплойта нет | Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled duricyrus · imap · CWE-407 | Высокая7,5 | — | 3,1 % | 1 сент. 2021 г. |
31Наблюдать | CVE-2015-8078Эксплойта нет | Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspcyrus · imap · CWE-189 | Высокая7,5 | — | 2,8 % | 3 дек. 2015 г. |
30Наблюдать | CVE-2002-2043Эксплойта нет | SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute acyrus · sasl | Высокая7,5 | — | 1,3 % | 31 дек. 2002 г. |
28Наблюдать | CVE-2004-0884Эксплойта нет | The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available Scyrus · sasl | Высокая7,2 | — | 0,5 % | 27 янв. 2005 г. |
28Наблюдать | CVE-2026-61915Эксплойта нет | An issue was discovered in Cyrus IMAP before 3.12.4.cyrus · imap · CWE-415 | Высокая7,1 | — | 0,3 % | 9 сент. 2026 г. |
26Наблюдать | CVE-2019-19783Эксплойта нет | An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8.cyrus · imap · CWE-269 | Средняя6,5 | — | 1,7 % | 16 дек. 2019 г. |
26Наблюдать | CVE-2026-61908Эксплойта нет | An issue was discovered in Cyrus IMAP before 3.12.4.cyrus · imap · CWE-125 | Средняя6,5 | — | 0,2 % | 9 сент. 2026 г. |
20Наблюдать | CVE-2026-61910Эксплойта нет | An issue was discovered in Cyrus IMAP before 3.12.4.cyrus · imap · CWE-863 | Средняя5,0 | — | 0,2 % | 9 сент. 2026 г. |
18Наблюдать | CVE-2021-32056Эксплойта нет | Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on servecyrus · imap · CWE-732 | Средняя4,3 | — | 1,7 % | 10 мая 2021 г. |
17Наблюдать | CVE-2026-61911Эксплойта нет | An issue was discovered in Cyrus IMAP before 3.12.4.cyrus · imap · CWE-497 | Средняя4,3 | — | 0,2 % | 9 сент. 2026 г. |
17Наблюдать | CVE-2026-61909Эксплойта нет | An issue was discovered in Cyrus IMAP before 3.12.4.cyrus · imap · CWE-420 | Средняя4,3 | — | 0,2 % | 9 сент. 2026 г. |
11Наблюдать | CVE-2006-1721Эксплойта нет | digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allocyrus · sasl · CWE-20 | Низкая2,6 | — | 2,5 % | 11 апр. 2006 г. |
- CVE-2002-225342В плане
Multiple buffer overflows in Cyrus Sieve / libSieve 2.1.2 and earlier allow remote attackers to execute arbitrary code via (1) a long header
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %cyrus · libsieve31 дек. 2002 г.
- CVE-2019-1135641В плане
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %cyrus · imap3 июн. 2019 г.
- CVE-2019-1892840В плане
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentic
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cyrus · imap15 нояб. 2019 г.
- CVE-2017-1423037Наблюдать
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST comma
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %cyrus · imap10 сент. 2017 г.
- CVE-2006-250236Наблюдать
Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers t
СредняяCVSS 5,1Готовый эксплойтEPSS 53 %cyrus · imapd22 мая 2006 г.
- CVE-2005-054631Наблюдать
Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imap
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %cyrus · imapd2 мая 2005 г.
- CVE-2005-037331Наблюдать
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bu
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %cyrus · sasl7 окт. 2004 г.
- CVE-2011-337231Наблюдать
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an A
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %cyrus · imapd24 дек. 2011 г.
- CVE-2015-807631Наблюдать
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %cyrus · imap3 дек. 2015 г.
- CVE-2015-807731Наблюдать
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unsp
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %cyrus · imap3 дек. 2015 г.
- CVE-2021-3358231Наблюдать
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled duri
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %cyrus · imap1 сент. 2021 г.
- CVE-2015-807831Наблюдать
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unsp
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %cyrus · imap3 дек. 2015 г.
- CVE-2002-204330Наблюдать
SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cyrus · sasl31 дек. 2002 г.
- CVE-2004-088428Наблюдать
The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available S
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %cyrus · sasl27 янв. 2005 г.
- CVE-2026-6191528Наблюдать
An issue was discovered in Cyrus IMAP before 3.12.4.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %cyrus · imap9 сент. 2026 г.
- CVE-2019-1978326Наблюдать
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %cyrus · imap16 дек. 2019 г.
- CVE-2026-6190826Наблюдать
An issue was discovered in Cyrus IMAP before 3.12.4.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %cyrus · imap9 сент. 2026 г.
- CVE-2026-6191020Наблюдать
An issue was discovered in Cyrus IMAP before 3.12.4.
СредняяCVSS 5,0Эксплойта нетEPSS 0 %cyrus · imap9 сент. 2026 г.
- CVE-2021-3205618Наблюдать
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on serve
СредняяCVSS 4,3Эксплойта нетEPSS 2 %cyrus · imap10 мая 2021 г.
- CVE-2026-6191117Наблюдать
An issue was discovered in Cyrus IMAP before 3.12.4.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %cyrus · imap9 сент. 2026 г.
- CVE-2026-6190917Наблюдать
An issue was discovered in Cyrus IMAP before 3.12.4.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %cyrus · imap9 сент. 2026 г.
- CVE-2006-172111Наблюдать
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allo
НизкаяCVSS 2,6Эксплойта нетEPSS 2 %cyrus · sasl11 апр. 2006 г.