Vulnerabilities > Dovecot > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-10-15 | CVE-2008-4578 | Permissions, Privileges, and Access Controls vulnerability in Dovecot The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes. | 5.0 |
2008-03-10 | CVE-2008-1218 | Credentials Management vulnerability in Dovecot Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified. | 6.8 |
2008-03-06 | CVE-2008-1199 | Configuration vulnerability in Dovecot Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack. | 4.4 |
2008-01-04 | CVE-2007-6598 | Permissions, Privileges, and Access Controls vulnerability in Dovecot Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password. | 6.8 |
2007-08-08 | CVE-2007-4211 | Unspecified vulnerability in Dovecot The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command. network dovecot | 6.0 |
2007-04-25 | CVE-2007-2231 | Remote Information Disclosure vulnerability in Dovecot Zlib Plugin Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. network dovecot | 4.3 |