imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.
Loading...
Loading...
imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.
April 18, 2014
May 6, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2014-2014
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.