← Vulnerability feed

Vulnerability record · CVE-2001-1154 · published 30 August 2001

CVE-2001-1154: Carnegie mellon university cyrus imap server vulnerability

CCarnegie Mellon University · Cyrus Imap Server

Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.

5.0 CVSS 2.0 Medium EPSS 1.6% · top 25.0%
5.0CVSS 2.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-1154 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-1011Carnegie mellon university cyrus imap server vulnerabilityStack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbit…EPSS 5.8%10.0CVE-2004-1012Carnegie mellon university cyrus imap server vulnerabilityThe argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a c…EPSS 6.0%10.0CVE-2004-1013Carnegie mellon university cyrus imap server vulnerabilityThe argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via cer…EPSS 5.8%10.0CVE-2004-1015Carnegie mellon university cyrus imap server vulnerabilityBuffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option enabled, may allow remote attackers to execute arbit…EPSS 5.2%10.0CVE-2004-1067Carnegie mellon university cyrus imap server vulnerabilityOff-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attacker…EPSS 5.2%10.0CVE-1999-0879Bsdi bsd os vulnerabilityBuffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.EPSS 9.7%10.0CVE-1999-0798Bsdi bsd os vulnerabilityBuffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.EPSS 1.6%10.0CVE-1999-0002Bsdi bsd os memory buffer overflow vulnerabilityBuffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.EPSS 28%

Source: NIST National Vulnerability Database (record CVE-2001-1154), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.