Логотип exploitDog
bind:"CVE-2011-2167" OR bind:"CVE-2011-4318" OR bind:"CVE-2011-2166"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2011-2167" OR bind:"CVE-2011-4318" OR bind:"CVE-2011-2166"

Количество 16

Количество 16

oracle-oval логотип

ELSA-2013-0520

больше 12 лет назад

ELSA-2013-0520: dovecot security and bug fix update (LOW)

EPSS: Низкий
ubuntu логотип

CVE-2011-2167

около 14 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
redhat логотип

CVE-2011-2167

больше 14 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2011-2167

около 14 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2011-2167

около 14 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot ...

CVSS2: 6.5
EPSS: Низкий
github логотип

GHSA-w278-mxj8-7r9j

больше 3 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

EPSS: Низкий
ubuntu логотип

CVE-2011-4318

больше 12 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2011-4318

почти 14 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2011-4318

больше 12 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2011-4318

больше 12 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostn ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-2166

около 14 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
redhat логотип

CVE-2011-2166

больше 14 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2011-2166

около 14 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2011-2166

около 14 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user a ...

CVSS2: 6.5
EPSS: Низкий
github логотип

GHSA-w2rf-p589-jpp8

больше 3 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

EPSS: Низкий
github логотип

GHSA-v9cm-xcfc-8942

больше 3 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2013-0520

ELSA-2013-0520: dovecot security and bug fix update (LOW)

больше 12 лет назад
ubuntu логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
1%
Низкий
около 14 лет назад
redhat логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 3.6
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot ...

CVSS2: 6.5
1%
Низкий
около 14 лет назад
github логотип
GHSA-w278-mxj8-7r9j

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostn ...

CVSS2: 5.8
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
0%
Низкий
около 14 лет назад
redhat логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 3.6
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
0%
Низкий
около 14 лет назад
debian логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user a ...

CVSS2: 6.5
0%
Низкий
около 14 лет назад
github логотип
GHSA-w2rf-p589-jpp8

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-v9cm-xcfc-8942

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу