dovecot-news@dovecot.org
- 1 participants
- 472 discussions
1
0
1
1
1
1
CVE-2024-23184: Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive
by Aki Tuomi 14 Aug '24
by Aki Tuomi 14 Aug '24
14 Aug '24
1
0
CVE-2024-23185: Very large headers can cause resource exhaustion when parsing message
by Aki Tuomi 14 Aug '24
by Aki Tuomi 14 Aug '24
14 Aug '24
1
0
1
0
1
0
1
0
1
0
1
0
1
0
CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used
by Aki Tuomi 07 Jul '22
by Aki Tuomi 07 Jul '22
07 Jul '22
1
1
1
0
1
1
1
0
1
0
1
0
1
0
1
0
1
0
1
1
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
04 Jan '21
1
0
1
0
1
0
1
0
1
0
1
0
1
0
12 Aug '20
1
0
12 Aug '20
1
0
CVE-2020-12100: Receiving mail with deeply nested MIME parts leads to resource exhaustion.
by Aki Tuomi 12 Aug '20
by Aki Tuomi 12 Aug '20
12 Aug '20
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
1
1
0
CVE-2020-7046: Truncated UTF-8 can be used to DoS submission-login and lmtp processes
by Aki Tuomi 12 Feb '20
by Aki Tuomi 12 Feb '20
12 Feb '20
1
0
12 Feb '20
1
0
1
0
2
1
1
0
1
0
1
0
1
0
1
1
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
CVE-2019-11499: Submission-login crashes when authentication is started over TLS secured channel and invalid authentication message is sent
by Aki Tuomi 30 Apr '19
by Aki Tuomi 30 Apr '19
30 Apr '19
1
0
CVE-2019-11494: Submission-login crashes with signal 11 due to null pointer access when authentication is aborted by disconnecting.
by Aki Tuomi 30 Apr '19
by Aki Tuomi 30 Apr '19
30 Apr '19
1
0
1
0
1
0
CVE-2019-10691: JSON encoder in Dovecot 2.3 incorrecty assert-crashes when encountering invalid UTF-8 characters.
by Aki Tuomi 18 Apr '19
by Aki Tuomi 18 Apr '19
18 Apr '19
1
0
1
0
1
1
CVE-2019-7524: Buffer overflow when reading extension header from dovecot index files
by Aki Tuomi 28 Mar '19
by Aki Tuomi 28 Mar '19
28 Mar '19
1
0
1
0
1
0
1
0
1
0
1
0
05 Feb '19
1
0
1
0
1
0
1
0
2
1
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
11 Apr '17
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
1
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0
1
0