Количество 9
Количество 9
CVE-2025-59031
Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known.
CVE-2025-59031
Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known.
CVE-2025-59031
Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known.
CVE-2025-59031
Dovecot has provided a script to use for attachment to text conversion ...
GHSA-7r6x-855q-h59r
Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known.
BDU:2026-10394
Уязвимость почтового сервера Dovecot, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260707-73-0035
Уязвимость dovecot
SUSE-SU-2026:1641-1
Security update for dovecot22
openSUSE-SU-2026:20554-1
Security update for dovecot24
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-59031 Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
CVE-2025-59031 Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
CVE-2025-59031 Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
CVE-2025-59031 Dovecot has provided a script to use for attachment to text conversion ... | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
GHSA-7r6x-855q-h59r Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
BDU:2026-10394 Уязвимость почтового сервера Dovecot, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
ROS-20260707-73-0035 Уязвимость dovecot | CVSS3: 4.3 | 0% Низкий | 24 дня назад | |
SUSE-SU-2026:1641-1 Security update for dovecot22 | 3 месяца назад | |||
openSUSE-SU-2026:20554-1 Security update for dovecot24 | 4 месяца назад |
Уязвимостей на страницу