Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 19

Количество 19

fstec логотип

BDU:2026-10388

4 месяца назад

Уязвимость почтовых серверов Dovecot и OX Dovecot Pro, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260707-73-0042

24 дня назад

Уязвимость dovecot

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-27857

4 месяца назад

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2026-27857

4 месяца назад

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-27857

4 месяца назад

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-27857

4 месяца назад

Sending "NOOP (((...)))" command with 4000 parenthesis open+close resu ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-j26c-8p6m-gpfj

4 месяца назад

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 4.3
EPSS: Низкий
rocky логотип

RLSA-2026:19364

2 месяца назад

Important: dovecot security update

EPSS: Низкий
rocky логотип

RLSA-2026:19149

2 месяца назад

Important: dovecot security update

EPSS: Низкий
rocky логотип

RLSA-2026:13857

3 месяца назад

Important: dovecot security update

EPSS: Низкий
rocky логотип

RLSA-2026:13830

3 месяца назад

Important: dovecot security update

EPSS: Низкий
rocky логотип

RLSA-2026:13498

3 месяца назад

Important: dovecot security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19364

около 1 месяца назад

ELSA-2026-19364: dovecot security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19149

15 дней назад

ELSA-2026-19149: dovecot security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-13857

3 месяца назад

ELSA-2026-13857: dovecot security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-13830

3 месяца назад

ELSA-2026-13830: dovecot security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-13498

3 месяца назад

ELSA-2026-13498: dovecot security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1641-1

3 месяца назад

Security update for dovecot22

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20554-1

4 месяца назад

Security update for dovecot24

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-10388

Уязвимость почтовых серверов Dovecot и OX Dovecot Pro, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
4 месяца назад
redos логотип
ROS-20260707-73-0042

Уязвимость dovecot

CVSS3: 7.5
1%
Низкий
24 дня назад
ubuntu логотип
CVE-2026-27857

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 4.3
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-27857

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-27857

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 4.3
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-27857

Sending "NOOP (((...)))" command with 4000 parenthesis open+close resu ...

CVSS3: 4.3
1%
Низкий
4 месяца назад
github логотип
GHSA-j26c-8p6m-gpfj

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 4.3
1%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:19364

Important: dovecot security update

2 месяца назад
rocky логотип
RLSA-2026:19149

Important: dovecot security update

2 месяца назад
rocky логотип
RLSA-2026:13857

Important: dovecot security update

3 месяца назад
rocky логотип
RLSA-2026:13830

Important: dovecot security update

3 месяца назад
rocky логотип
RLSA-2026:13498

Important: dovecot security update

3 месяца назад
oracle-oval логотип
ELSA-2026-19364

ELSA-2026-19364: dovecot security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-19149

ELSA-2026-19149: dovecot security update (IMPORTANT)

15 дней назад
oracle-oval логотип
ELSA-2026-13857

ELSA-2026-13857: dovecot security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-13830

ELSA-2026-13830: dovecot security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-13498

ELSA-2026-13498: dovecot security update (IMPORTANT)

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1641-1

Security update for dovecot22

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20554-1

Security update for dovecot24

4 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.