Show filters
53 Total Results
Displaying 51-53 of 53
Sort by:
Attacker Value
Unknown

CVE-2007-6598

Disclosure Date: January 04, 2008 (last updated October 04, 2023)
Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
0
Attacker Value
Unknown

CVE-2007-4211

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
0
Attacker Value
Unknown

CVE-2007-2231

Disclosure Date: April 25, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
0