Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

ubuntu логотип

CVE-2026-42007

16 дней назад

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-42007

16 дней назад

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-42007

16 дней назад

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-42007

16 дней назад

An attacker that has valid credentials can use a Sieve script with the ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-9h72-j5f4-5cpc

16 дней назад

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3919-1

11 дней назад

Security update for dovecot22

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21720-1

12 дней назад

Security update for dovecot24

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-42007

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 9.1
0%
Низкий
16 дней назад
redhat логотип
CVE-2026-42007

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 9.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-42007

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 9.1
0%
Низкий
16 дней назад
debian логотип
CVE-2026-42007

An attacker that has valid credentials can use a Sieve script with the ...

CVSS3: 9.1
0%
Низкий
16 дней назад
github логотип
GHSA-9h72-j5f4-5cpc

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 9.1
0%
Низкий
16 дней назад
suse-cvrf логотип
SUSE-SU-2026:3919-1

Security update for dovecot22

11 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21720-1

Security update for dovecot24

12 дней назад

Уязвимостей на страницу