HomeDovecotCVE-2010-3304

CVE-2010-3304

UNKNOWN
6.4CVSS
Published: 2010-09-24
Updated: 2025-04-11
AI Analysis

Description

The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.

CVSS Metrics

Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Access Vector
network
Access Cmplx
low
Auth
none
Confidentiality
partial
Integrity
partial
Availability
none
Weaknesses
CWE-264

Metadata

Primary Vendor
DOVECOT
Published
9/24/2010
Last Modified
4/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

dovecot : dovecotdovecot : dovecotdovecot : dovecotdovecot : dovecotdovecot : dovecotdovecot : dovecotdovecot : dovecotdovecot : dovecotdovecot : dovecotdovecot : dovecotdovecot : dovecotdovecot : dovecotdovecot : dovecot

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2010-3304 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com