Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

oracle-oval логотип

ELSA-2013-0520

больше 13 лет назад

ELSA-2013-0520: dovecot security and bug fix update (LOW)

EPSS: Низкий
ubuntu логотип

CVE-2011-2167

около 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
redhat логотип

CVE-2011-2167

около 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2011-2167

около 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2011-2167

около 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot ...

CVSS2: 6.5
EPSS: Низкий
github логотип

GHSA-w278-mxj8-7r9j

около 4 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

EPSS: Низкий
ubuntu логотип

CVE-2011-4318

больше 13 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2011-4318

больше 14 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2011-4318

больше 13 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2011-4318

больше 13 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostn ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-2166

около 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
redhat логотип

CVE-2011-2166

около 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2011-2166

около 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2011-2166

около 15 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user a ...

CVSS2: 6.5
EPSS: Низкий
github логотип

GHSA-w2rf-p589-jpp8

около 4 лет назад

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

EPSS: Низкий
github логотип

GHSA-v9cm-xcfc-8942

около 4 лет назад

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2013-0520

ELSA-2013-0520: dovecot security and bug fix update (LOW)

больше 13 лет назад
ubuntu логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
2%
Низкий
около 15 лет назад
redhat логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 3.6
2%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

CVSS2: 6.5
2%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2167

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot ...

CVSS2: 6.5
2%
Низкий
около 15 лет назад
github логотип
GHSA-w278-mxj8-7r9j

script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

2%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

CVSS2: 5.8
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4318

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostn ...

CVSS2: 5.8
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
2%
Низкий
около 15 лет назад
redhat логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 3.6
2%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

CVSS2: 6.5
2%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2166

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user a ...

CVSS2: 6.5
2%
Низкий
около 15 лет назад
github логотип
GHSA-w2rf-p589-jpp8

Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

1%
Низкий
около 4 лет назад
github логотип
GHSA-v9cm-xcfc-8942

script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу