Known vulnerabilities in Cyrus SASL
Vendor:
Carnegie Mellon University
Software:
Cyrus SASL
Software CPE:
cpe:2.3:a:carnegie_mellon_university:cyrus_sasl:*:*:*:*:*:*:*:*
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.1.28
2.1.27
2.1.26
2.1.25
2.1.24
2.1.23
2.1.22
2.1.21
2.1.20
2.1.19
2.1.18
2.1.17
2.1.16-BETA
2.1.15
2.1.14
2.1.13
2.1.12
2.1.11
2.1.10
2.1.9
2.1.8
2.1.7
2.1.6
2.1.5
2.1.4
2.1.3-BETA
2.1.2
2.1.1
2.1.0
2.0.5-BETA
2.0.4-BETA
2.0.3-BETA
2.0.2-ALPHA
2.0.0-ALPHA
1.5.26
1.5.25
1.5.24
1.5.22
1.5.21
1.5.20
1.5.19
1.5.18
1.5.17
1.5.16
1.5.15
1.5.14
1.5.13
1.5.12
1.5.11
1.5.10
1.5.9
1.5.5
1.5.3
1.5.2
1.5.0
1.4.1
1.3b1
1.2b3
1.2b2
1.2b1
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU60842 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2022-24407 |
CWE-89 | High | 2.1.28 | 24.02.2022 |
SB2022022409 SB2022022410 SB2022022421 and 67 more |
||
| #VU23796 - Out-of-bounds write CVE-2019-19906 |
CWE-787 | Medium | 2.1.28 | 23.12.2019 |
SB2019122303 SB2019122304 SB2020012820 and 15 more |
||
| #VU33161 - NULL Pointer Dereference CVE-2013-4122 |
CWE-476 | Medium | 2.1.24 | 27.10.2013 |
SB2013102701 SB2015111011 SB2014051307 and 1 more |