James server
This hub aggregates every CVE we track for James server, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3MEDIUM1
Monthly trend
0
0
0
0
0
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 4 most recently published vulnerabilities affecting James server.
- CVE-2024-37358Apache James: denial of service through the use of IMAP literals8.6
- CVE-2024-45626Apache James: denial of service through JMAP HTML to text conversion6.5
- CVE-2017-12628The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX s...7.8
- CVE-2015-7611Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified vectors.8.1
Product normalization is registry-driven with AI assist and human review. How it works