peter bassill · operator
$ cve CVE-2019-11356 JSON

CVE-2019-11356

9.8
CRITICAL · CVSS 3.1 · EPSS 7.6% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.62% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2019-06-03
Last modified2026-06-17

Affected (8)

VendorProduct
canonicalubuntu linux
cyrusimap
debiandebian linux
fedoraprojectfedora
redhatenterprise linux
redhatenterprise linux eus
redhatenterprise linux server aus
redhatenterprise linux server tus

References

→ the Explorer  ·  watch your stack  ·  NVD