Search CVE reports
1 – 10 of 105 results
An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by that host can be injected as an internal authentication field. Any...
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail....
1 affected package
dovecot
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| dovecot | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |