CVE-2011-3481
Description
The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.
No summary for this CVE yet.
CVSS Vector Breakdown
Exploitability
AV:NAccess VectorNetwork
AC:MAccess ComplexityMedium
Au:NAuthenticationNone
Impact
C:NConfidentialityNone
I:NIntegrityNone
A:PAvailabilityPartial
Weaknesses
Affected Products
cmu
oss-projectaka cveclient, panda3d, cyrus imap server
and 1 more affected products View all →
Exploitability
Official Patch Available
References
http://git.cyrusimap.org/cyrus-imapd/commit/?id=6e776956a1a9dfa58eacdd0ddd52644009eac9e5
git.cyrusimap.org
http://bugzilla.cyrusimap.org/show_bug.cgi?id=3463
bugzilla.cyrusimap.org
http://bugzilla.cyrusimap.org/show_bug.cgi?id=2772
bugzilla.cyrusimap.org
and 3 more references View all →
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2011-3481 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows
