Dovecot

Dovecot

53 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Published 09.12.2013 16:36:47
  • Last modified 11.04.2025 00:51:21

checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descri...

  • EPSS 0.38%
  • Published 07.03.2013 01:55:01
  • Last modified 11.04.2025 00:51:21

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows...

  • EPSS 0.42%
  • Published 24.05.2011 23:55:04
  • Last modified 11.04.2025 00:51:21

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

  • EPSS 0.26%
  • Published 24.05.2011 23:55:04
  • Last modified 11.04.2025 00:51:21

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

  • EPSS 6.54%
  • Published 24.05.2011 23:55:04
  • Last modified 11.04.2025 00:51:21

lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a cr...

  • EPSS 1.06%
  • Published 06.10.2010 21:00:01
  • Last modified 11.04.2025 00:51:21

Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.

  • EPSS 0.3%
  • Published 06.10.2010 21:00:01
  • Last modified 11.04.2025 00:51:21

Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a ma...

  • EPSS 0.18%
  • Published 06.10.2010 17:00:17
  • Last modified 11.04.2025 00:51:21

plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ...

  • EPSS 0.4%
  • Published 06.10.2010 17:00:17
  • Last modified 11.04.2025 00:51:21

plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ...

  • EPSS 1.71%
  • Published 24.09.2010 19:00:04
  • Last modified 11.04.2025 00:51:21

The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.