CVE-2013-6171
- EPSS 0.25%
- Veröffentlicht 09.12.2013 16:36:47
- Zuletzt bearbeitet 11.04.2025 00:51:21
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descri...
CVE-2011-4318
- EPSS 0.38%
- Veröffentlicht 07.03.2013 01:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows...
CVE-2011-2167
- EPSS 0.42%
- Veröffentlicht 24.05.2011 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
CVE-2011-2166
- EPSS 0.26%
- Veröffentlicht 24.05.2011 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
- EPSS 6.54%
- Veröffentlicht 24.05.2011 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a cr...
- EPSS 1.06%
- Veröffentlicht 06.10.2010 21:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
CVE-2010-3779
- EPSS 0.3%
- Veröffentlicht 06.10.2010 21:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a ma...
CVE-2010-3707
- EPSS 0.18%
- Veröffentlicht 06.10.2010 17:00:17
- Zuletzt bearbeitet 11.04.2025 00:51:21
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ...
CVE-2010-3706
- EPSS 0.4%
- Veröffentlicht 06.10.2010 17:00:17
- Zuletzt bearbeitet 11.04.2025 00:51:21
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ...
CVE-2010-3304
- EPSS 1.71%
- Veröffentlicht 24.09.2010 19:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.