Search CVE reports
11 – 20 of 105 results
OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path. An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
acl: lda_mailbox_autocreate can bypass acl restrictions. None
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
IMAP Compression Can Reveal Whether a Small Synced Email Body Matches Sender-Chosen Text. When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
v2.4.3 regression: managesieve-login pre-auth infinite loop. An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU.
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
MySQL multi-byte escaping wrong. None
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
IMAP THREAD O(M=C2=B3) CPU DoS via CRC32 Hash Collision in strmap (mail-index-strmap.c / hash2.c). An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table,...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
imap-hibernate can be crashed. An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process.
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
IMAP THREAD REFERENCES O(N=C2=B2) CPU DoS via Crafted References Header (index-thread-links.c). An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
pigeonhole: Stack Buffer Underflow in Pigeonhole ManageSieve CHECKSCRIPT/PUTSCRIPT. An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Dovecot IMAP LIST match_sub() Exponential Backtracking =E2=80=94 CPU Denial of Service. An attacker that has valid credentials can use IMAP LIST commnd to consume CPU.
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |