dovecot kayıtları
dovecot üreticisine ait 69 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %98,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation11
- CWE-400 Uncontrolled Resource Consumption7
- CWE-264 Permissions, Privileges, and Access Controls6
- CWE-287 Improper Authentication4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-476 NULL Pointer Dereference3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
69 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
58Planlayın | CVE-2019-11500İstismar yok | In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings.dovecot · dovecot · CWE-787 | Kritik9,8 | — | %62,6 | 29 Ağu 2019 |
45Planlayın | CVE-2020-7046İstismar yok | lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrateddovecot · dovecot · CWE-835 | Yüksek7,5 | — | %51,3 | 12 Şub 2020 |
37İzleyin | CVE-2016-8652İstismar yok | The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) dovecot · dovecot · CWE-20 | Orta5,9 | — | %48,2 | 16 Şub 2017 |
36İzleyin | CVE-2022-30550İstismar yok | An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20.dovecot · dovecot · CWE-287 | Yüksek8,8 | — | %2,2 | 17 Tem 2022 |
36İzleyin | CVE-2026-27851İstismar yok | When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enablidovecot · dovecot · CWE-235 | Kritik9,1 | — | %0,6 | 12 May 2026 |
33İzleyin | CVE-2017-14461İstismar yok | A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensidovecot · dovecot · CWE-125 | Yüksek7,1 | — | %16,7 | 2 Mar 2018 |
32İzleyin | CVE-2020-10957İstismar yok | In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash indovecot · dovecot · CWE-476 | Yüksek7,5 | — | %7,2 | 18 May 2020 |
32İzleyin | CVE-2020-12674İstismar yok | In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.dovecot · dovecot · CWE-125 | Yüksek7,5 | — | %6,2 | 12 Ağu 2020 |
32İzleyin | CVE-2020-12673İstismar yok | In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.dovecot · dovecot · CWE-125 | Yüksek7,5 | — | %6,2 | 12 Ağu 2020 |
32İzleyin | CVE-2020-12100İstismar yok | In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resourdovecot · dovecot · CWE-674 | Yüksek7,5 | — | %5,3 | 12 Ağu 2020 |
32İzleyin | CVE-2026-24031Kavram kanıtı | Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin.dovecot · dovecot · CWE-89 | Yüksek8,2 | — | %0,4 | 27 Mar 2026 |
31İzleyin | CVE-2020-25275İstismar yok | Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message withdovecot · dovecot · CWE-20 | Yüksek7,5 | — | %4,7 | 4 Oca 2021 |
31İzleyin | CVE-2017-2669İstismar yok | Dovecot before version 2.2.29 is vulnerable to a denial of service.dovecot · dovecot · CWE-20 | Yüksek7,5 | — | %4,5 | 21 Haz 2018 |
31İzleyin | CVE-2009-3235İstismar yok | Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, dovecot · dovecot · CWE-119 | Yüksek7,5 | — | %4,0 | 17 Eyl 2009 |
31İzleyin | CVE-2017-15132İstismar yok | A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0.dovecot · dovecot · CWE-400 | Yüksek7,5 | — | %3,1 | 25 Oca 2018 |
31İzleyin | CVE-2019-10691İstismar yok | The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate witdovecot · dovecot | Yüksek7,5 | — | %2,8 | 24 Nis 2019 |
31İzleyin | CVE-2019-11499İstismar yok | In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured chdovecot · dovecot | Yüksek7,5 | — | %2,5 | 8 May 2019 |
31İzleyin | CVE-2019-11494İstismar yok | In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during thedovecot · dovecot · CWE-476 | Yüksek7,5 | — | %2,4 | 8 May 2019 |
31İzleyin | CVE-2008-4577İstismar yok | The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypassdovecot · dovecot · CWE-863 | Yüksek7,5 | — | %2,3 | 15 Eki 2008 |
31İzleyin | CVE-2019-7524İstismar yok | In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can bdovecot · dovecot · CWE-119 | Yüksek7,8 | — | %1,2 | 28 Mar 2019 |
30İzleyin | CVE-2026-27858İstismar yok | Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.dovecot · dovecot · CWE-400 | Yüksek7,5 | — | %1,0 | 27 Mar 2026 |
30İzleyin | CVE-2026-27857İstismar yok | Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage.dovecot · dovecot · CWE-400 | Yüksek7,5 | — | %0,8 | 27 Mar 2026 |
30İzleyin | CVE-2025-59032İstismar yok | ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response.dovecot · dovecot · CWE-20 | Yüksek7,5 | — | %0,7 | 27 Mar 2026 |
30İzleyin | CVE-2025-59028İstismar yok | When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to faidovecot · dovecot · CWE-20 | Yüksek7,5 | — | %0,4 | 27 Mar 2026 |
29İzleyin | CVE-2008-1218Kavram kanıtı | Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackdovecot · dovecot · CWE-255 | Orta6,8 | — | %7,3 | 10 Mar 2008 |
- CVE-2019-1150058Planlayın
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings.
KritikCVSS 9,8İstismar yokEPSS %63dovecot · dovecot29 Ağu 2019
- CVE-2020-704645Planlayın
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated
YüksekCVSS 7,5İstismar yokEPSS %51dovecot · dovecot12 Şub 2020
- CVE-2016-865237İzleyin
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash)
OrtaCVSS 5,9İstismar yokEPSS %48dovecot · dovecot16 Şub 2017
- CVE-2022-3055036İzleyin
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20.
YüksekCVSS 8,8İstismar yokEPSS %2dovecot · dovecot17 Tem 2022
- CVE-2026-2785136İzleyin
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabli
KritikCVSS 9,1İstismar yokEPSS %1dovecot · dovecot12 May 2026
- CVE-2017-1446133İzleyin
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensi
YüksekCVSS 7,1İstismar yokEPSS %17dovecot · dovecot2 Mar 2018
- CVE-2020-1095732İzleyin
In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in
YüksekCVSS 7,5İstismar yokEPSS %7dovecot · dovecot18 May 2020
- CVE-2020-1267432İzleyin
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
YüksekCVSS 7,5İstismar yokEPSS %6dovecot · dovecot12 Ağu 2020
- CVE-2020-1267332İzleyin
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
YüksekCVSS 7,5İstismar yokEPSS %6dovecot · dovecot12 Ağu 2020
- CVE-2020-1210032İzleyin
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resour
YüksekCVSS 7,5İstismar yokEPSS %5dovecot · dovecot12 Ağu 2020
- CVE-2026-2403132İzleyin
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin.
YüksekCVSS 8,2Kavram kanıtıEPSS %0dovecot · dovecot27 Mar 2026
- CVE-2020-2527531İzleyin
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with
YüksekCVSS 7,5İstismar yokEPSS %5dovecot · dovecot4 Oca 2021
- CVE-2017-266931İzleyin
Dovecot before version 2.2.29 is vulnerable to a denial of service.
YüksekCVSS 7,5İstismar yokEPSS %4dovecot · dovecot21 Haz 2018
- CVE-2009-323531İzleyin
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve,
YüksekCVSS 7,5İstismar yokEPSS %4dovecot · dovecot17 Eyl 2009
- CVE-2017-1513231İzleyin
A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0.
YüksekCVSS 7,5İstismar yokEPSS %3dovecot · dovecot25 Oca 2018
- CVE-2019-1069131İzleyin
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate wit
YüksekCVSS 7,5İstismar yokEPSS %3dovecot · dovecot24 Nis 2019
- CVE-2019-1149931İzleyin
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured ch
YüksekCVSS 7,5İstismar yokEPSS %3dovecot · dovecot8 May 2019
- CVE-2019-1149431İzleyin
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the
YüksekCVSS 7,5İstismar yokEPSS %2dovecot · dovecot8 May 2019
- CVE-2008-457731İzleyin
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass
YüksekCVSS 7,5İstismar yokEPSS %2dovecot · dovecot15 Eki 2008
- CVE-2019-752431İzleyin
In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can b
YüksekCVSS 7,8İstismar yokEPSS %1dovecot · dovecot28 Mar 2019
- CVE-2026-2785830İzleyin
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.
YüksekCVSS 7,5İstismar yokEPSS %1dovecot · dovecot27 Mar 2026
- CVE-2026-2785730İzleyin
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage.
YüksekCVSS 7,5İstismar yokEPSS %1dovecot · dovecot27 Mar 2026
- CVE-2025-5903230İzleyin
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response.
YüksekCVSS 7,5İstismar yokEPSS %1dovecot · dovecot27 Mar 2026
- CVE-2025-5902830İzleyin
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fai
YüksekCVSS 7,5İstismar yokEPSS %0dovecot · dovecot27 Mar 2026
- CVE-2008-121829İzleyin
Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attack
OrtaCVSS 6,8Kavram kanıtıEPSS %7dovecot · dovecot10 Mar 2008