Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 45

Количество 45

redos логотип

ROS-20260707-73-0039

2 месяца назад

Уязвимость dovecot

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-27856

6 месяцев назад

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2026-27856

6 месяцев назад

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-27856

6 месяцев назад

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2026-27856

6 месяцев назад

Doveadm credentials are verified using direct comparison which is susc ...

CVSS3: 7.4
EPSS: Низкий
redos логотип

ROS-20260707-80-0039

2 месяца назад

Уязвимость dovecot

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-mv3x-9fw3-qf38

6 месяцев назад

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
EPSS: Низкий
fstec логотип

BDU:2026-10401

6 месяцев назад

Уязвимость компонента doveadm почтового сервера Dovecot, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.9
EPSS: Низкий
redos логотип

ROS-20260707-73-0041

2 месяца назад

Уязвимость dovecot

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2026-27858

6 месяцев назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-27858

6 месяцев назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-27858

6 месяцев назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-27858

6 месяцев назад

Attacker can send a specifically crafted message before authentication ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-27857

6 месяцев назад

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2026-27857

6 месяцев назад

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-27857

6 месяцев назад

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-27857

6 месяцев назад

Sending "NOOP (((...)))" command with 4000 parenthesis open+close resu ...

CVSS3: 4.3
EPSS: Низкий
redos логотип

ROS-20260707-80-0041

2 месяца назад

Уязвимость dovecot

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260707-80-0040

2 месяца назад

Уязвимость dovecot

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr7v-hj32-mr4r

6 месяцев назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redos логотип
ROS-20260707-73-0039

Уязвимость dovecot

CVSS3: 7.5
1%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-27856

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-27856

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-27856

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
0%
Низкий
6 месяцев назад
debian логотип
CVE-2026-27856

Doveadm credentials are verified using direct comparison which is susc ...

CVSS3: 7.4
0%
Низкий
6 месяцев назад
redos логотип
ROS-20260707-80-0039

Уязвимость dovecot

CVSS3: 5.9
0%
Низкий
2 месяца назад
github логотип
GHSA-mv3x-9fw3-qf38

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known.

CVSS3: 7.4
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-10401

Уязвимость компонента doveadm почтового сервера Dovecot, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.9
0%
Низкий
6 месяцев назад
redos логотип
ROS-20260707-73-0041

Уязвимость dovecot

CVSS3: 5.9
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-27858

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-27858

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-27858

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
debian логотип
CVE-2026-27858

Attacker can send a specifically crafted message before authentication ...

CVSS3: 7.5
1%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-27857

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 4.3
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-27857

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-27857

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Attacker could connect possibly from even a single IP and create 1000 connections to allocate 1 GB of memory, which would likely result in reaching VSZ limit and killing the process and its other proxied connections. Install fixed version, there is no other remediation. No publicly available exploits are known.

CVSS3: 4.3
1%
Низкий
6 месяцев назад
debian логотип
CVE-2026-27857

Sending "NOOP (((...)))" command with 4000 parenthesis open+close resu ...

CVSS3: 4.3
1%
Низкий
6 месяцев назад
redos логотип
ROS-20260707-80-0041

Уязвимость dovecot

CVSS3: 7.5
1%
Низкий
2 месяца назад
redos логотип
ROS-20260707-80-0040

Уязвимость dovecot

CVSS3: 7.5
1%
Низкий
2 месяца назад
github логотип
GHSA-xr7v-hj32-mr4r

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
1%
Низкий
6 месяцев назад

Уязвимостей на страницу