CVE-2014-0079: Zarafa
Medium severity, CVSS 5.0. EPSS: 1.9% chance of exploitation in the next 30 days.
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the password."
Affected products
- Zarafa Zarafa: up to and including 6.20; version 5.00 only; version 5.01 only; version 5.02 only; version 5.10 only; version 5.11 only; …
Published 2014-04-28. Last modified 2026-06-17.