Search CVE reports


Toggle filters

251 – 260 of 56459 results

Status is adjusted based on your filters.


CVE-2026-40203

Medium priority
Needs evaluation

IMAP Compression Can Reveal Whether a Small Synced Email Body Matches Sender-Chosen Text. When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both...

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40019

Medium priority
Needs evaluation

v2.4.3 regression: managesieve-login pre-auth infinite loop. An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU.

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40018

Medium priority
Needs evaluation

MySQL multi-byte escaping wrong. None

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40017

Medium priority
Needs evaluation

IMAP THREAD O(M=C2=B3) CPU DoS via CRC32 Hash Collision in strmap (mail-index-strmap.c / hash2.c). An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table,...

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40015

Medium priority
Needs evaluation

imap-hibernate can be crashed. An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process.

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40014

Medium priority
Needs evaluation

IMAP THREAD REFERENCES O(N=C2=B2) CPU DoS via Crafted References Header (index-thread-links.c). An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to...

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40013

Medium priority
Needs evaluation

pigeonhole: Stack Buffer Underflow in Pigeonhole ManageSieve CHECKSCRIPT/PUTSCRIPT. An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when...

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33607

Medium priority
Needs evaluation

Dovecot IMAP LIST match_sub() Exponential Backtracking =E2=80=94 CPU Denial of Service. An attacker that has valid credentials can use IMAP LIST commnd to consume CPU.

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33606

Medium priority
Needs evaluation

dsync: Mail content can cause dsync protocol injection. Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example...

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33605

Medium priority
Needs evaluation

managesieve-login: Pre-auth crash. An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating.

1 affected package

dovecot

Package 16.04 LTS
dovecot Needs evaluation
Show less packages