VYPR
Unrated severityNVD Advisory· Published Apr 28, 2014· Updated May 6, 2026

CVE-2014-0079

CVE-2014-0079

Description

The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the password."

Affected products

15
  • Zarafa/Zarafa15 versions
    cpe:2.3:a:zarafa:zarafa:*:*:*:*:*:*:*:*+ 14 more
    • cpe:2.3:a:zarafa:zarafa:*:*:*:*:*:*:*:*range: <=6.20
    • cpe:2.3:a:zarafa:zarafa:5.00:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:5.01:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:5.02:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:5.10:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:5.11:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:5.20:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:5.22:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:6.00:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:6.01:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:6.02:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:6.03:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:6.10:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:6.11:*:*:*:*:*:*:*
    • cpe:2.3:a:zarafa:zarafa:7.1.8:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.