VendorsApachejamesall versions
Vulnerabilities

Apache James

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2019-0228
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Published 2019-04-17 · Modified
9.8EPSS 0.095
CVE-2023-51518
Apache James server: Privilege escalation via JMX pre-authentication deserialisation
Published 2024-02-27 · Analyzed
9.8EPSS 0.012
CVE-2021-40525
Sieve file storage vulnerable to path traversal attacks
Published 2022-01-04 · Modified
9.1EPSS 0.037
CVE-2006-2806
The SMTP server in Apache Java Mail Enterprise Server (aka Apache James) 2.2.0 allows remote attackers to cause a denial of service (CPU consumption) via a long argument to the MAIL command.
Published 2006-06-05 · Modified
7.8EPSS 0.066
CVE-2023-26269
Apache James server: Privilege escalation through unauthenticated JMX
Published 2023-04-03 · Modified
7.8EPSS 0.007
CVE-2021-40110
Apache James IMAP vulnerable to a ReDoS
Published 2022-01-04 · Modified
7.5EPSS 0.029
CVE-2022-28220
STARTTLS command injection in Apache JAMES
Published 2022-09-08 · Modified
7.5EPSS 0.020
CVE-2023-51747
SMTP smuggling in Apache James
Published 2024-02-27 · Analyzed
7.1EPSS 0.010
CVE-2021-40111
Apache James IMAP parsing Denial Of Service
Published 2022-01-04 · Modified
6.5EPSS 0.021
CVE-2021-38542
Apache James vulnerable to STARTTLS command injection (IMAP and POP3)
Published 2022-01-04 · Modified
5.9EPSS 0.023
CVE-2022-45935
Apache James server: Temporary File Information Disclosure
Published 2023-01-06 · Modified
5.5EPSS 0.004
CVE-2022-45787
Apache James MIME4J: Temporary File Information Disclosure in MIME4J TempFileStorageProvider
Published 2023-01-06 · Modified
5.5EPSS 0.003
CVE-2004-2650
Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
Published 2005-12-09 · Modified
4.9EPSS 0.006
CVE-2022-22931
Path traversal in Apache James 3.6.1
Published 2022-02-07 · Modified
4.3EPSS 0.018