Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27858

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
Версия до 2.4.3 (исключая)
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*
Версия до 2.3.22.1 (исключая)
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*
Версия от 3.0.0 (включая) до 3.0.5 (исключая)
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*
Версия от 3.1.0 (включая) до 3.1.4 (исключая)

EPSS

Процентиль: 52%
0.0079
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
redhat
4 месяца назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
debian
4 месяца назад

Attacker can send a specifically crafted message before authentication ...

CVSS3: 7.5
redos
24 дня назад

Уязвимость dovecot

CVSS3: 7.5
github
4 месяца назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

EPSS

Процентиль: 52%
0.0079
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770