CVE-2015-8076: Cyrus Imap
High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.
The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.
Affected products
- Cyrus Imap: version 2.3.0 only; version 2.3.1 only; version 2.3.2 only; version 2.3.3 only; version 2.3.4 only; version 2.3.5 only; …
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
Published 2015-12-03. Last modified 2026-06-17.