CVE-2014-0037: Zarafa

Medium severity, CVSS 5.0. EPSS: 2.5% chance of exploitation in the next 30 days.

The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the username."

Affected products

  • Zarafa Zarafa: version 5.00 only; version 5.01 only; version 5.02 only; version 5.10 only; version 5.11 only; version 5.20 only; …

Published 2014-04-28. Last modified 2026-06-17.