Search CVE reports


Toggle filters

761 – 770 of 47438 results

Status is adjusted based on your filters.


CVE-2026-52681

Medium priority
Needs evaluation

Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is...

1 affected package

dovecot

Package 20.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-42395

Medium priority
Needs evaluation

A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial...

1 affected package

dovecot

Package 20.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-42393

Medium priority
Needs evaluation

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated...

1 affected package

dovecot

Package 20.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-42392

Medium priority
Needs evaluation

An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the...

1 affected package

dovecot

Package 20.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-42391

Medium priority
Needs evaluation

An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by...

1 affected package

dovecot

Package 20.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-42008

Medium priority
Needs evaluation

Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by that host can be injected as an internal authentication field. Any...

1 affected package

dovecot

Package 20.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-42007

Medium priority
Needs evaluation

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail....

1 affected package

dovecot

Package 20.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40205

Medium priority
Needs evaluation

An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries...

1 affected package

dovecot

Package 20.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40204

Medium priority
Needs evaluation

None None None No publicly available exploits are known.

1 affected package

dovecot

Package 20.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40203

Medium priority
Needs evaluation

When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a...

1 affected package

dovecot

Package 20.04 LTS
dovecot Needs evaluation
Show less packages