Vulnerabilities > Dovecot > Dovecot > 1.0.rc5

DATE CVE VULNERABILITY TITLE RISK
2008-10-15 CVE-2008-4578 Permissions, Privileges, and Access Controls vulnerability in Dovecot
The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
network
low complexity
dovecot CWE-264
5.0
2008-03-06 CVE-2008-1199 Configuration vulnerability in Dovecot
Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
local
dovecot CWE-16
4.4
2007-04-25 CVE-2007-2231 Remote Information Disclosure vulnerability in Dovecot Zlib Plugin
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a ..
network
dovecot
4.3