Skip to main content

Vendor/product archive

cyrus / sasl CVEs

Beta · best-effort

4 CVEs tagged to cyrus / sasl0 Critical, 3 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2006-1721

Published Apr 11, 2006

digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0884

Published Jan 27, 2005

The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to find all available SASL plug-ins, which allows local users…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2043

Published Dec 31, 2002

SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arb…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1