CVE-2015-8077: Cyrus Imap

High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.

Affected products

  • Cyrus Imap: version 2.3.0 only; version 2.3.1 only; version 2.3.2 only; version 2.3.3 only; version 2.3.4 only; version 2.3.5 only; …
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.2 only

Published 2015-12-03. Last modified 2026-06-17.