CVE-2014-0079: Zarafa

Medium severity, CVSS 5.0. EPSS: 1.9% chance of exploitation in the next 30 days.

The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the password."

Affected products

  • Zarafa Zarafa: up to and including 6.20; version 5.00 only; version 5.01 only; version 5.02 only; version 5.10 only; version 5.11 only; …

Published 2014-04-28. Last modified 2026-06-17.