Search CVE reports


Toggle filters

121 – 130 of 33165 results

Status is adjusted based on your filters.


CVE-2026-27856

Medium priority
Vulnerable

doveadm: Credentials verified without timing safety. Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring...

1 affected package

dovecot

Package 24.04 LTS
dovecot Vulnerable
Show less packages

CVE-2026-27855

Medium priority
Vulnerable

auth: OTP driver vulnerable to replay attack. Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so...

1 affected package

dovecot

Package 24.04 LTS
dovecot Vulnerable
Show less packages

CVE-2026-24031

Medium priority
Not affected

v2.4/v3.1 regression: SQL injection allows bypassing authentication. Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user...

1 affected package

dovecot

Package 24.04 LTS
dovecot Not affected
Show less packages

CVE-2026-0394

Medium priority
Vulnerable

auth: Path traversal in passwd-file passdb using `%d` (domain) escapes base directory and opens `/etc/passwd`Pre-auth path traversal in passwd-file passdb using `%d` (domain) escapes base directory and opens `/etc/passwd`. When...

1 affected package

dovecot

Package 24.04 LTS
dovecot Vulnerable
Show less packages

CVE-2025-67030

Medium priority

Not in release

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

1 affected package

plexus-utils

Package 24.04 LTS
plexus-utils Not in release
Show less packages

CVE-2025-59032

Medium priority
Vulnerable

v2.4/v3.1 regression: Pigeonhole: ManageSieve panic occurs with sieve-connect as a client. ManageSieve AUTHENTICATE command crashes when using literal as ASL initial response. This can be used to crash ManageSieve service...

1 affected package

dovecot

Package 24.04 LTS
dovecot Vulnerable
Show less packages

CVE-2025-59031

Low priority
Vulnerable

decode2text.sh OOXML extraction may follow symlinks and read unintended files during indexing. Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker...

1 affected package

dovecot

Package 24.04 LTS
dovecot Vulnerable
Show less packages

CVE-2025-59028

Medium priority
Not affected

Invalid base64 authentication can cause DoS for other logins. When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can...

1 affected package

dovecot

Package 24.04 LTS
dovecot Not affected
Show less packages

CVE-2026-4775

Medium priority
Needs evaluation

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an...

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 24.04 LTS
tiff Needs evaluation
qtwebengine-opensource-src Needs evaluation
texmaker Needs evaluation
gdal Not affected
neuron Not affected
Show less packages

CVE-2026-4751

Medium priority
Needs evaluation

NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0.

1 affected package

tmate

Package 24.04 LTS
tmate Needs evaluation
Show less packages