Apache / James
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-51747 | SMTP smuggling in Apache James | HIGH | 7.4 | Feb 27, 2024 |
| CVE-2023-51518 | Apache James server: Privilege escalation via JMX pre-authentication deserialisation | CRITICAL | 9.3 | Feb 27, 2024 |
| CVE-2023-26269 | Apache James server: Privilege escalation through unauthenticated JMX | HIGH | 7.8 | Apr 3, 2023 |
| CVE-2022-45935 | Apache James server: Temporary File Information Disclosure | MEDIUM | 5.5 | Jan 6, 2023 |
| CVE-2022-45787 | Apache James MIME4J: Temporary File Information Disclosure in MIME4J TempFileStorageProvider | MEDIUM | 5.5 | Jan 6, 2023 |
| CVE-2022-28220 | STARTTLS command injection in Apache JAMES | HIGH | 7.5 | Sep 8, 2022 |
| CVE-2022-22931 | Path traversal in Apache James 3.6.1 | MEDIUM | 4.3 | Feb 7, 2022 |
| CVE-2021-40525 | Sieve file storage vulnerable to path traversal attacks | CRITICAL | 9.1 | Jan 4, 2022 |
| CVE-2021-40111 | Apache James IMAP parsing Denial Of Service | MEDIUM | 6.5 | Jan 4, 2022 |
| CVE-2021-40110 | Apache James IMAP vulnerable to a ReDoS | HIGH | 7.5 | Jan 4, 2022 |
| CVE-2021-38542 | Apache James vulnerable to STARTTLS command injection (IMAP and POP3) | MEDIUM | 5.9 | Jan 4, 2022 |
| CVE-2019-0228 | pdfbox: XML External Entity (XXE) attacks via a crafted XFDF | CRITICAL | 9.8 | Apr 17, 2019 |
| CVE-2006-2806 | The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a lon… | HIGH | 7.8 | Jun 5, 2006 |
| CVE-2004-2650 | Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the ret… | MEDIUM | 4.9 | Dec 9, 2005 |
Showing 1 to 14 of 14 CVEs