在 Cyrus IMAP 3.12.4 之前版本中发现一个问题:JMAP 电子邮件标头 Blob ID 可以引用一个越界索引。经过身份验证的用户可以尝试下载一个构造好的、形式为 的 JMAP Blob ID,这可能导致在下载过程中读取超出内部 数组末尾的内存,从而暴露相邻的堆内存。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cyrusimap | Cyrus IMAP | < 3.8.8 |
affected |
3.9.0< 3.10.4 |
affected | ||
3.11.0< 3.12.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cyrusimap | Cyrus IMAP | 0 ~ 3.8.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61907 | 4.3 MEDIUM | Cyrus IMAP 3.12.4前JMAP Snooze ACL绕过 |
| CVE-2026-61911 | 4.3 MEDIUM | Cyrus IMAP 3.12.4前Sieve邮箱存在性预言 |
| CVE-2026-61915 | 4.2 MEDIUM | Cyrus IMAP 3.12.4前 认证用户致CalDAV进程崩溃 |
| CVE-2026-61910 | 3.5 LOW | Cyrus IMAP 3.12.4前共享邮箱权限控制缺陷 |
| CVE-2026-61909 | 3.5 LOW | Cyrus IMAP 3.12.4前 CalDAV多获取ACL绕过 |
No comments yet