cyrus kayıtları
cyrus üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %4,5
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %81,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-189 Numeric Errors2
- CWE-20 Improper Input Validation2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-287 Improper Authentication1
- CWE-407 Inefficient Algorithmic Complexity1
- CWE-415 Double Free1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2002-2253İstismar yok | Multiple buffer overflows in Cyrus Sieve / libSieve 2.1.2 and earlier allow remote attackers to execute arbitrary code via (1) a long headercyrus · libsieve · CWE-119 | Kritik10,0 | — | %6,6 | 31 Ara 2002 |
41Planlayın | CVE-2019-11356İstismar yok | The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code viacyrus · imap · CWE-787 | Kritik9,8 | — | %7,6 | 3 Haz 2019 |
40Planlayın | CVE-2019-18928İstismar yok | Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authenticcyrus · imap | Kritik9,8 | — | %2,4 | 15 Kas 2019 |
37İzleyin | CVE-2017-14230İstismar yok | In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST commacyrus · imap · CWE-20 | Kritik9,1 | — | %2,2 | 10 Eyl 2017 |
36İzleyin | CVE-2006-2502Silahlaştırılmış | Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers tcyrus · imapd | Orta5,1 | — | %53,3 | 22 May 2006 |
31İzleyin | CVE-2005-0546İstismar yok | Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imapcyrus · imapd | Yüksek7,5 | — | %4,2 | 2 May 2005 |
31İzleyin | CVE-2005-0373İstismar yok | Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bucyrus · sasl | Yüksek7,5 | — | %3,9 | 7 Eki 2004 |
31İzleyin | CVE-2011-3372İstismar yok | imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an Acyrus · imapd · CWE-287 | Yüksek7,5 | — | %3,3 | 24 Ara 2011 |
31İzleyin | CVE-2015-8076İstismar yok | The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers tocyrus · imap · CWE-119 | Yüksek7,5 | — | %3,3 | 3 Ara 2015 |
31İzleyin | CVE-2015-8077İstismar yok | Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspcyrus · imap · CWE-189 | Yüksek7,5 | — | %3,3 | 3 Ara 2015 |
31İzleyin | CVE-2021-33582İstismar yok | Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled duricyrus · imap · CWE-407 | Yüksek7,5 | — | %3,1 | 1 Eyl 2021 |
31İzleyin | CVE-2015-8078İstismar yok | Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspcyrus · imap · CWE-189 | Yüksek7,5 | — | %2,8 | 3 Ara 2015 |
30İzleyin | CVE-2002-2043İstismar yok | SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute acyrus · sasl | Yüksek7,5 | — | %1,3 | 31 Ara 2002 |
28İzleyin | CVE-2004-0884İstismar yok | The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available Scyrus · sasl | Yüksek7,2 | — | %0,5 | 27 Oca 2005 |
28İzleyin | CVE-2026-61915İstismar yok | An issue was discovered in Cyrus IMAP before 3.12.4.cyrus · imap · CWE-415 | Yüksek7,1 | — | %0,3 | 9 Eyl 2026 |
26İzleyin | CVE-2019-19783İstismar yok | An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8.cyrus · imap · CWE-269 | Orta6,5 | — | %1,7 | 16 Ara 2019 |
26İzleyin | CVE-2026-61908İstismar yok | An issue was discovered in Cyrus IMAP before 3.12.4.cyrus · imap · CWE-125 | Orta6,5 | — | %0,2 | 9 Eyl 2026 |
20İzleyin | CVE-2026-61910İstismar yok | An issue was discovered in Cyrus IMAP before 3.12.4.cyrus · imap · CWE-863 | Orta5,0 | — | %0,2 | 9 Eyl 2026 |
18İzleyin | CVE-2021-32056İstismar yok | Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on servecyrus · imap · CWE-732 | Orta4,3 | — | %1,7 | 10 May 2021 |
17İzleyin | CVE-2026-61911İstismar yok | An issue was discovered in Cyrus IMAP before 3.12.4.cyrus · imap · CWE-497 | Orta4,3 | — | %0,2 | 9 Eyl 2026 |
17İzleyin | CVE-2026-61909İstismar yok | An issue was discovered in Cyrus IMAP before 3.12.4.cyrus · imap · CWE-420 | Orta4,3 | — | %0,2 | 9 Eyl 2026 |
11İzleyin | CVE-2006-1721İstismar yok | digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allocyrus · sasl · CWE-20 | Düşük2,6 | — | %2,5 | 11 Nis 2006 |
- CVE-2002-225342Planlayın
Multiple buffer overflows in Cyrus Sieve / libSieve 2.1.2 and earlier allow remote attackers to execute arbitrary code via (1) a long header
KritikCVSS 10,0İstismar yokEPSS %7cyrus · libsieve31 Ara 2002
- CVE-2019-1135641Planlayın
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via
KritikCVSS 9,8İstismar yokEPSS %8cyrus · imap3 Haz 2019
- CVE-2019-1892840Planlayın
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentic
KritikCVSS 9,8İstismar yokEPSS %2cyrus · imap15 Kas 2019
- CVE-2017-1423037İzleyin
In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST comma
KritikCVSS 9,1İstismar yokEPSS %2cyrus · imap10 Eyl 2017
- CVE-2006-250236İzleyin
Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers t
OrtaCVSS 5,1SilahlaştırılmışEPSS %53cyrus · imapd22 May 2006
- CVE-2005-054631İzleyin
Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imap
YüksekCVSS 7,5İstismar yokEPSS %4cyrus · imapd2 May 2005
- CVE-2005-037331İzleyin
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bu
YüksekCVSS 7,5İstismar yokEPSS %4cyrus · sasl7 Eki 2004
- CVE-2011-337231İzleyin
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an A
YüksekCVSS 7,5İstismar yokEPSS %3cyrus · imapd24 Ara 2011
- CVE-2015-807631İzleyin
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to
YüksekCVSS 7,5İstismar yokEPSS %3cyrus · imap3 Ara 2015
- CVE-2015-807731İzleyin
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unsp
YüksekCVSS 7,5İstismar yokEPSS %3cyrus · imap3 Ara 2015
- CVE-2021-3358231İzleyin
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled duri
YüksekCVSS 7,5İstismar yokEPSS %3cyrus · imap1 Eyl 2021
- CVE-2015-807831İzleyin
Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unsp
YüksekCVSS 7,5İstismar yokEPSS %3cyrus · imap3 Ara 2015
- CVE-2002-204330İzleyin
SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute a
YüksekCVSS 7,5İstismar yokEPSS %1cyrus · sasl31 Ara 2002
- CVE-2004-088428İzleyin
The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available S
YüksekCVSS 7,2İstismar yokEPSS %1cyrus · sasl27 Oca 2005
- CVE-2026-6191528İzleyin
An issue was discovered in Cyrus IMAP before 3.12.4.
YüksekCVSS 7,1İstismar yokEPSS %0cyrus · imap9 Eyl 2026
- CVE-2019-1978326İzleyin
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8.
OrtaCVSS 6,5İstismar yokEPSS %2cyrus · imap16 Ara 2019
- CVE-2026-6190826İzleyin
An issue was discovered in Cyrus IMAP before 3.12.4.
OrtaCVSS 6,5İstismar yokEPSS %0cyrus · imap9 Eyl 2026
- CVE-2026-6191020İzleyin
An issue was discovered in Cyrus IMAP before 3.12.4.
OrtaCVSS 5,0İstismar yokEPSS %0cyrus · imap9 Eyl 2026
- CVE-2021-3205618İzleyin
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on serve
OrtaCVSS 4,3İstismar yokEPSS %2cyrus · imap10 May 2021
- CVE-2026-6191117İzleyin
An issue was discovered in Cyrus IMAP before 3.12.4.
OrtaCVSS 4,3İstismar yokEPSS %0cyrus · imap9 Eyl 2026
- CVE-2026-6190917İzleyin
An issue was discovered in Cyrus IMAP before 3.12.4.
OrtaCVSS 4,3İstismar yokEPSS %0cyrus · imap9 Eyl 2026
- CVE-2006-172111İzleyin
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allo
DüşükCVSS 2,6İstismar yokEPSS %2cyrus · sasl11 Nis 2006