Search CVE reports
501 – 510 of 44457 results
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script used :fcc (to save a copy of the sent message) could deliver...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other...
1 affected package
cyrus-imapd
| Package | 22.04 LTS |
|---|---|
| cyrus-imapd | Needs evaluation |
Not in release
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer matchRegexPattern closure in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go...
1 affected package
dasel
| Package | 22.04 LTS |
|---|---|
| dasel | Not in release |