VYPR

Courier IMAP

Sign in to watch

by Inter7

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2004-07770.040.16Oct 20, 2004Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.
CVE-2004-02240.000.04Apr 15, 2004Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range."
CVE-2003-00400.000.00Feb 19, 2003SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.