Количество 9
Количество 9
BDU:2026-10407
Уязвимость почтовых серверов Dovecot и OX Dovecot Pro, связанная с неправильным контролем идентификаторов ресурсов («внедрение ресурсов»), позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260707-73-0044
Уязвимость dovecot
CVE-2026-33603
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
CVE-2026-33603
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
CVE-2026-33603
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
CVE-2026-33603
Attacker can use a specially crafted base64 exchange between Dovecot a ...
GHSA-gxj9-f8v6-q8h3
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
SUSE-SU-2026:2645-1
Security update for dovecot22
openSUSE-SU-2026:21109-1
Security update for dovecot24
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-10407 Уязвимость почтовых серверов Dovecot и OX Dovecot Pro, связанная с неправильным контролем идентификаторов ресурсов («внедрение ресурсов»), позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
ROS-20260707-73-0044 Уязвимость dovecot | CVSS3: 5.3 | 0% Низкий | 24 дня назад | |
CVE-2026-33603 Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known. | CVSS3: 6.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-33603 Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known. | CVSS3: 6.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-33603 Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known. | CVSS3: 6.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-33603 Attacker can use a specially crafted base64 exchange between Dovecot a ... | CVSS3: 6.8 | 0% Низкий | 3 месяца назад | |
GHSA-gxj9-f8v6-q8h3 Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known. | CVSS3: 6.8 | 0% Низкий | 3 месяца назад | |
SUSE-SU-2026:2645-1 Security update for dovecot22 | около 1 месяца назад | |||
openSUSE-SU-2026:21109-1 Security update for dovecot24 | около 1 месяца назад |
Уязвимостей на страницу