CVE-2021-28994

kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP headers.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
kopanogroupware_core
𝑥
≤ 8.7.16
kopanogroupware_core
9.0.0 ≤
𝑥
≤ 9.1.0
kopanogroupware_core
10.0.0 ≤
𝑥
≤ 10.0.7
kopanogroupware_core
11.0.0 ≤
𝑥
≤ 11.0.1
zarafazarafa
6.30.0 ≤
𝑥
≤ 7.2.6
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kopanocore
noble
dne
mantic
dne
lunar
dne
kinetic
ignored
jammy
needed
impish
ignored
hirsute
ignored
groovy
ignored
focal
needed
bionic
needed
xenial
dne
trusty
dne