Cyrus is a modestly represented vendor of mail-server infrastructure, particularly its IMAP server and related protocol libraries such as SASL and libsieve, which are embedded in critical messaging deployments across organizations. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency to acquire public exploit code; the recurring weakness classes—improper input validation, memory-buffer violations, sensitive-information exposure, and authentication bypass—reflect the parsing and access-control complexity inherent to mail-protocol handlers. Defenders should prioritize updates for mail-server tiers and inventory the use of Cyrus components in other messaging stacks; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cyrus over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2502MEDIUM Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER | May 22, 2006 | 5.1 | 59 | NO | YES |
CVE-2019-11356CRITICAL The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an eve | Jun 3, 2019 | 9.8 | 33 | NO | NO |
CVE-2002-2253HIGH Multiple buffer overflows in Cyrus Sieve / libSieve 2.1.2 and earlier allow remote attackers to execute arbitrary code via (1) a long header name, (2) a long IMAP flag, or (3) a sc | Dec 31, 2002 | 10.0 | 33 | NO | NO |
CVE-2019-18928CRITICAL Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous r | Nov 15, 2019 | 9.8 | 31 | NO | NO |
CVE-2017-14230CRITICAL In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, w | Sep 10, 2017 | 9.1 | 29 | NO | NO |
CVE-2021-33582HIGH Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there | Sep 1, 2021 | 7.5 | 26 | NO | NO |
CVE-2011-3372HIGH imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an | Dec 24, 2011 | 7.5 | 24 | NO | NO |
CVE-2019-19783MEDIUM An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options a | Dec 16, 2019 | 6.5 | 23 | NO | NO |
CVE-2004-0884HIGH The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users t | Jan 27, 2005 | 7.2 | 23 | NO | NO |
CVE-2015-8078HIGH Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to ur | Dec 3, 2015 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cyrus.
Media articles that mention a CVE ID that affects a product developed by Cyrus — matched by CVE ID, not by vendor name.