Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Dovecot
(Dovecot)Repositories | https://github.com/dovecot/core |
#Vulnerabilities | 53 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2008-03-06 | CVE-2008-1199 | Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack. | Dovecot | N/A | ||
2008-01-04 | CVE-2007-6598 | Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password. | Dovecot | N/A | ||
2007-08-08 | CVE-2007-4211 | The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command. | Dovecot | N/A | ||
2007-04-25 | CVE-2007-2231 | Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name. | Dovecot | N/A |