Логотип exploitDog
bind:"CVE-2011-2167" OR bind:"CVE-2011-4318" OR bind:"CVE-2011-2166"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2011-2167" OR bind:"CVE-2011-4318" OR bind:"CVE-2011-2166"

Количество 16

Количество 16

oracle-oval логотип

ELSA-2013-0520

около 13 лет назад

ELSA-2013-0520: dovecot security and bug fix update (LOW)

EPSS: Низкий
ubuntu логотип

CVE-2011-2167

почти 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
redhat логотип

CVE-2011-2167

почти 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2011-2167

почти 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2011-2167

почти 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot ...

CVSS2: 6.5
EPSS: Низкий
github логотип

GHSA-w278-mxj8-7r9j

почти 4 года назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

EPSS: Низкий
ubuntu логотип

CVE-2011-4318

около 13 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2011-4318

больше 14 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2011-4318

около 13 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2011-4318

около 13 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostn ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-2166

почти 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
redhat логотип

CVE-2011-2166

почти 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2011-2166

почти 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2011-2166

почти 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user a ...

CVSS2: 6.5
EPSS: Низкий
github логотип

GHSA-w2rf-p589-jpp8

почти 4 года назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

EPSS: Низкий
github логотип

GHSA-v9cm-xcfc-8942

почти 4 года назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2013-0520

ELSA-2013-0520: dovecot security and bug fix update (LOW)

около 13 лет назад
ubuntu логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
0%
Низкий
почти 15 лет назад
redhat логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 3.6
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot ...

CVSS2: 6.5
0%
Низкий
почти 15 лет назад
github логотип
GHSA-w278-mxj8-7r9j

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
0%
Низкий
около 13 лет назад
redhat логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
0%
Низкий
около 13 лет назад
debian логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostn ...

CVSS2: 5.8
0%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
0%
Низкий
почти 15 лет назад
redhat логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 3.6
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user a ...

CVSS2: 6.5
0%
Низкий
почти 15 лет назад
github логотип
GHSA-w2rf-p589-jpp8

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

0%
Низкий
почти 4 года назад
github логотип
GHSA-v9cm-xcfc-8942

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу