VYPR

Courier IMAP

by Double Precision Incorporated

CVEs (5)

  • CVE-2026-67194MedJul 29, 2026
    risk 0.35cvss 6.5epss 0.00

    Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized…

  • CVE-2004-0777Oct 20, 2004
    risk 0.04cvss epss 0.11

    Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.

  • CVE-2007-2173Apr 24, 2007
    risk 0.00cvss epss 0.05

    Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.

  • CVE-2004-0224Apr 15, 2004
    risk 0.00cvss epss 0.03

    Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range."

  • CVE-2003-0040Feb 19, 2003
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.