Search CVE reports
81 – 90 of 42470 results
v3.0.2+ regression: Message headers MIME parameter parsing can cause excessive CPU usage. A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message...
1 affected package
dovecot
| Package | 18.04 LTS |
|---|---|
| dovecot | Vulnerable |
managesieve-login out-of-memory DoS. Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by...
1 affected package
dovecot
| Package | 18.04 LTS |
|---|---|
| dovecot | Vulnerable |
imap-login: Excessive memory usage DoS. Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for...
1 affected package
dovecot
| Package | 18.04 LTS |
|---|---|
| dovecot | Not affected |
doveadm: Credentials verified without timing safety. Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring...
1 affected package
dovecot
| Package | 18.04 LTS |
|---|---|
| dovecot | Not affected |
auth: OTP driver vulnerable to replay attack. Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so...
1 affected package
dovecot
| Package | 18.04 LTS |
|---|---|
| dovecot | Vulnerable |
v2.4/v3.1 regression: SQL injection allows bypassing authentication. Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user...
1 affected package
dovecot
| Package | 18.04 LTS |
|---|---|
| dovecot | Not affected |
auth: Path traversal in passwd-file passdb using `%d` (domain) escapes base directory and opens `/etc/passwd`Pre-auth path traversal in passwd-file passdb using `%d` (domain) escapes base directory and opens `/etc/passwd`. When...
1 affected package
dovecot
| Package | 18.04 LTS |
|---|---|
| dovecot | Vulnerable |
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
1 affected package
plexus-utils
| Package | 18.04 LTS |
|---|---|
| plexus-utils | Needs evaluation |
v2.4/v3.1 regression: Pigeonhole: ManageSieve panic occurs with sieve-connect as a client. ManageSieve AUTHENTICATE command crashes when using literal as ASL initial response. This can be used to crash ManageSieve service...
1 affected package
dovecot
| Package | 18.04 LTS |
|---|---|
| dovecot | Vulnerable |
decode2text.sh OOXML extraction may follow symlinks and read unintended files during indexing. Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker...
1 affected package
dovecot
| Package | 18.04 LTS |
|---|---|
| dovecot | Vulnerable |