CVE-2014-0037: Zarafa
Medium severity, CVSS 5.0. EPSS: 2.5% chance of exploitation in the next 30 days.
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the username."
Affected products
- Zarafa Zarafa: version 5.00 only; version 5.01 only; version 5.02 only; version 5.10 only; version 5.11 only; version 5.20 only; …
Published 2014-04-28. Last modified 2026-06-17.