Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.1%—CMU Cyrus Imap Server14/9/201116/6/2026
The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.
ModificadaAlta (7.5)5.4%—CMU Cyrus Imap Server14/9/201116/6/2026
Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.
ModificadaMedia (5.1)4.0%—CMU Cyrus Imap Server23/5/201116/6/2026
The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a…
ModificadaMedia (4.4)0.48%—CMU Cyrus Imap Server8/9/200916/6/2026
Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use…
ModificadaAlta (10)5.2%—Carnegie Mellon University Cyrus Imap ServerRedhat Fedora CoreUbuntu Linux10/1/200516/6/2026
Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.
ModificadaAlta (10)5.2%—Carnegie Mellon University Cyrus Imap ServerRedhat Fedora CoreUbuntu Linux10/1/200516/6/2026
Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option enabled, may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2004-1011.
ModificadaAlta (10)5.8%—Carnegie Mellon University Cyrus Imap ServerOpenpkgConectiva LinuxRedhat Fedora Core+210/1/200516/6/2026
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulnerability than CVE-2004-1015.
ModificadaAlta (10)5.8%—Carnegie Mellon University Cyrus Imap ServerOpenpkgConectiva LinuxRedhat Fedora Core+210/1/200516/6/2026
The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment error that leads to an out-of-bounds memory corruption.
ModificadaAlta (10)6.0%—Carnegie Mellon University Cyrus Imap ServerOpenpkgConectiva LinuxRedhat Fedora Core+210/1/200516/6/2026
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index increment error that leads to an out-of-bounds memory corruption.
ModificadaAlta (7.5)17%—Carnegie Mellon University Cyrus Imap Server14/6/200416/6/2026
Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different vulnerability than CVE-2002-1347.
ModificadaMedia (5)1.6%—Carnegie Mellon University Cyrus Imap ServerBsdi BSD OS30/8/200116/6/2026
Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.