Vulnerabilidades en cyrusimap

15 resultados
Análisis Vexday

Cyrusimap apresenta 9 vulnerabilidades no histórico, todas publicadas nos últimos 90 dias, indicando atividade recente de descoberta. Nenhuma está atualmente sob ataque ativo (KEV) e não há críticas CVSS, reduzindo o risco imediato. A fraqueza dominante é CWE-863 (controle de acesso inadequado), padrão para este tipo de software de infraestrutura.

CVE-2026-61907MEDIUMAn issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert perEPSS 0.4%CVE-2026-47084MEDIUMAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-aEPSS 0.3%CVE-2026-47083MEDIUMAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH comEPSS 0.3%CVE-2026-47082MEDIUMAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whEPSS 0.3%CVE-2026-47085MEDIUMAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker kEPSS 0.3%CVE-2026-47087LOWAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted EPSS 0.3%CVE-2026-47089MEDIUMAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated EPSS 0.3%CVE-2026-47086LOWAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could EPSS 0.3%CVE-2026-47088LOWAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticatedEPSS 0.3%CVE-2026-61915MEDIUMAn issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a CyrEPSS 0.3%CVE-2026-47081LOWAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. EPSS 0.2%CVE-2026-61908LOWAn issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated userEPSS 0.2%CVE-2026-61911MEDIUMAn issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve EPSS 0.2%CVE-2026-61909LOWAn issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shEPSS 0.2%CVE-2026-61910LOWAn issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticateEPSS 0.2%