Vulnerabilities > Dovecot > Low

DATE CVE VULNERABILITY TITLE RISK
2019-11-05 CVE-2016-4983 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
local
low complexity
dovecot opensuse redhat CWE-732
2.1
2010-10-06 CVE-2010-3779 Permissions, Privileges, and Access Controls vulnerability in Dovecot
Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
network
dovecot CWE-264
3.5
2008-11-01 CVE-2008-4870 Incorrect Permission Assignment for Critical Resource vulnerability in Dovecot 1.0.7
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
local
low complexity
dovecot CWE-732
2.1