Apache / James Server
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-37358 | Apache James: denial of service through the use of IMAP literals | HIGH | 8.6 | Feb 6, 2025 |
| CVE-2024-45626 | Apache James: denial of service through JMAP HTML to text conversion | HIGH | 7.5 | Feb 6, 2025 |
| CVE-2023-51518 | Apache James server: Privilege escalation via JMX pre-authentication deserialisation | CRITICAL | 9.3 | Feb 27, 2024 |
| CVE-2023-26269 | Apache James server: Privilege escalation through unauthenticated JMX | HIGH | 7.8 | Apr 3, 2023 |
| CVE-2017-12628 | The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbi… | HIGH | 7.8 | Oct 20, 2017 |
| CVE-2015-7611 | Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified vectors. | HIGH | 8.1 | Jun 7, 2016 |
Showing 1 to 6 of 6 CVEs