CVE-2018-0682: Neo Debun Imap

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not properly manage sessions, which allows remote attackers to read/send mail or change the configuration via unspecified vectors.

Affected products

  • Neo Debun Imap: up to and including 3.3i_r4.0
  • Neo Debun Pop: up to and including 3.3p_r4.0

Published 2018-11-15. Last modified 2026-06-17.