Search CVE reports


Toggle filters

1681 – 1690 of 37432 results

Status is adjusted based on your filters.


CVE-2026-40018

Medium priority
Needs evaluation

None None None No publicly available exploits are known.

1 affected package

dovecot

Package 26.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40017

Medium priority
Needs evaluation

An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to the size of the message. This is...

1 affected package

dovecot

Package 26.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40015

Medium priority
Needs evaluation

An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated...

1 affected package

dovecot

Package 26.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40014

Medium priority
Needs evaluation

An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox,...

1 affected package

dovecot

Package 26.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-40013

Medium priority
Needs evaluation

An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an...

1 affected package

dovecot

Package 26.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33607

Medium priority
Needs evaluation

An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage and kill the offending process and lock account....

1 affected package

dovecot

Package 26.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33606

Medium priority
Needs evaluation

Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify...

1 affected package

dovecot

Package 26.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33605

Medium priority
Needs evaluation

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection...

1 affected package

dovecot

Package 26.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33604

Medium priority
Needs evaluation

An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending in the message body to bypass the outbound protection that prevents message content from...

1 affected package

dovecot

Package 26.04 LTS
dovecot Needs evaluation
Show less packages

CVE-2026-33263

Medium priority
Needs evaluation

When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode (default for community releases), only the...

1 affected package

dovecot

Package 26.04 LTS
dovecot Needs evaluation
Show less packages