Skip to content

CVE-2014-4366

Mail in Apple iOS before 8 does not prevent sending a LOGIN command to a LOGINDISABLED IMAP server, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0078 (0.8%)
Percentile: 73.8%
EPSS: 2026-05-06

Affects

apple:iphone_os

Technical description

Mail in Apple iOS before 8 does not prevent sending a LOGIN command to a LOGINDISABLED IMAP server, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.

Published: 9/18/2014, 10:55:08 AM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam