Количество 20
Количество 20
ELSA-2008-0297
ELSA-2008-0297: dovecot security and bug fix update (LOW)

CVE-2007-6598
Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

CVE-2007-6598
Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

CVE-2007-6598
Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
CVE-2007-6598
Dovecot before 1.0.10, with certain configuration options including us ...
GHSA-grp6-gcpf-v967
Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

CVE-2007-2231
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.

CVE-2007-2231
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.

CVE-2007-2231
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
CVE-2007-2231
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dove ...
GHSA-8qfr-2vxg-8g3g
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.

CVE-2007-4211
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.

CVE-2007-4211
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
CVE-2007-4211
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated use ...

CVE-2008-1199
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

CVE-2008-1199
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

CVE-2008-1199
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
CVE-2008-1199
Dovecot before 1.0.11, when configured to use mail_extra_groups to all ...
GHSA-7qph-c6xr-695q
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
GHSA-778f-c3r9-6vmp
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
ELSA-2008-0297 ELSA-2008-0297: dovecot security and bug fix update (LOW) | около 17 лет назад | |||
![]() | CVE-2007-6598 Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password. | CVSS2: 6.8 | 2% Низкий | больше 17 лет назад |
![]() | CVE-2007-6598 Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password. | 2% Низкий | больше 17 лет назад | |
![]() | CVE-2007-6598 Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password. | CVSS2: 6.8 | 2% Низкий | больше 17 лет назад |
CVE-2007-6598 Dovecot before 1.0.10, with certain configuration options including us ... | CVSS2: 6.8 | 2% Низкий | больше 17 лет назад | |
GHSA-grp6-gcpf-v967 Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password. | 2% Низкий | около 3 лет назад | ||
![]() | CVE-2007-2231 Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name. | CVSS2: 4.3 | 1% Низкий | около 18 лет назад |
![]() | CVE-2007-2231 Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name. | 1% Низкий | больше 18 лет назад | |
![]() | CVE-2007-2231 Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name. | CVSS2: 4.3 | 1% Низкий | около 18 лет назад |
CVE-2007-2231 Directory traversal vulnerability in index/mbox/mbox-storage.c in Dove ... | CVSS2: 4.3 | 1% Низкий | около 18 лет назад | |
GHSA-8qfr-2vxg-8g3g Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name. | 1% Низкий | около 3 лет назад | ||
![]() | CVE-2007-4211 The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command. | 1% Низкий | почти 18 лет назад | |
![]() | CVE-2007-4211 The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command. | CVSS2: 6 | 1% Низкий | почти 18 лет назад |
CVE-2007-4211 The ACL plugin in Dovecot before 1.0.3 allows remote authenticated use ... | CVSS2: 6 | 1% Низкий | почти 18 лет назад | |
![]() | CVE-2008-1199 Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack. | CVSS2: 4.4 | 0% Низкий | больше 17 лет назад |
![]() | CVE-2008-1199 Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack. | CVSS2: 3.7 | 0% Низкий | больше 17 лет назад |
![]() | CVE-2008-1199 Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack. | CVSS2: 4.4 | 0% Низкий | больше 17 лет назад |
CVE-2008-1199 Dovecot before 1.0.11, when configured to use mail_extra_groups to all ... | CVSS2: 4.4 | 0% Низкий | больше 17 лет назад | |
GHSA-7qph-c6xr-695q The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command. | 1% Низкий | около 3 лет назад | ||
GHSA-778f-c3r9-6vmp Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack. | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу