Логотип exploitDog
bind:"CVE-2019-19783" OR bind:"CVE-2019-18928"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2019-19783" OR bind:"CVE-2019-18928"

Количество 12

Количество 12

oracle-oval логотип

ELSA-2020-4655

больше 5 лет назад

ELSA-2020-4655: cyrus-imapd security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2019-18928

около 6 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2019-18928

около 6 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2019-18928

около 6 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-18928

около 6 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-19783

около 6 лет назад

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-19783

около 6 лет назад

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-19783

около 6 лет назад

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-19783

около 6 лет назад

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0. ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-mpmx-j2j3-253q

больше 3 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-rv2p-w5h4-rfg3

больше 3 лет назад

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2020-01976

около 6 лет назад

Уязвимость множества элементов сервера электронной почты Cyrus IMAP, связанная с недостатком механизма проверки вводимых данных, позволяющая нарушителю оказать воздействие на целостность информации

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2020-4655

ELSA-2020-4655: cyrus-imapd security update (MODERATE)

больше 5 лет назад
ubuntu логотип
CVE-2019-18928

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 9.8
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-18928

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 7.4
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-18928

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 9.8
1%
Низкий
около 6 лет назад
debian логотип
CVE-2019-18928

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege ...

CVSS3: 9.8
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-19783

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.

CVSS3: 6.5
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-19783

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.

CVSS3: 6.5
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-19783

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.

CVSS3: 6.5
1%
Низкий
около 6 лет назад
debian логотип
CVE-2019-19783

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0. ...

CVSS3: 6.5
1%
Низкий
около 6 лет назад
github логотип
GHSA-mpmx-j2j3-253q

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-rv2p-w5h4-rfg3

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-01976

Уязвимость множества элементов сервера электронной почты Cyrus IMAP, связанная с недостатком механизма проверки вводимых данных, позволяющая нарушителю оказать воздействие на целостность информации

CVSS3: 6.5
1%
Низкий
около 6 лет назад

Уязвимостей на страницу