Skip to main content

Vendor/product archive

apache / james_server CVEs

Beta · best-effort

4 CVEs tagged to apache / james_server0 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-45626

Published Feb 6, 2025

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Us…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37358

Published Feb 6, 2025

Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be u…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12628

Published Oct 20, 2017

The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As J…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7611

Published Jun 7, 2016

Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified vectors.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1