Imapsync is a focused command-line utility for migrating messages between IMAP servers, and its limited but targeted exposure centers on the imapsync product itself. The durable signal reflects the tool's direct handling of mailbox credentials and file operations, with recurrent vulnerabilities in credential exposure and improper file-access resolution. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Imapsync Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2014MEDIUM imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain creden | Apr 18, 2014 | 4.3 | 26 | NO | NO |
CVE-2023-34204MEDIUM imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these are typically world-writable, and thus (for example) an attack | May 30, 2023 | 6.5 | 17 | NO | NO |
CVE-2013-4279MEDIUM imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating system, and Perl version) to the developer's site. | Apr 18, 2014 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Imapsync Project.
Media articles that mention a CVE ID that affects a product developed by Imapsync Project — matched by CVE ID, not by vendor name.