Skip to content
Noroxi

dovecot records

69 published records for vendor dovecot.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
98.6%
Median publish → KEV
No record has entered KEV

All records

69 records
  • In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings.

    CriticalCVSS 9.8No exploitEPSS 63%

    dovecot · dovecotAug 29, 2019

  • lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated

    HighCVSS 7.5No exploitEPSS 51%

    dovecot · dovecotFeb 12, 2020

  • CVE-2016-8652
    37Monitor

    The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash)

    MediumCVSS 5.9No exploitEPSS 48%

    dovecot · dovecotFeb 16, 2017

  • An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20.

    HighCVSS 8.8No exploitEPSS 2%

    dovecot · dovecotJul 17, 2022

  • When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabli

    CriticalCVSS 9.1No exploitEPSS 1%

    dovecot · dovecotMay 12, 2026

  • A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensi

    HighCVSS 7.1No exploitEPSS 17%

    dovecot · dovecotMar 2, 2018

  • In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in

    HighCVSS 7.5No exploitEPSS 7%

    dovecot · dovecotMay 18, 2020

  • In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.

    HighCVSS 7.5No exploitEPSS 6%

    dovecot · dovecotAug 12, 2020

  • In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.

    HighCVSS 7.5No exploitEPSS 6%

    dovecot · dovecotAug 12, 2020

  • In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resour

    HighCVSS 7.5No exploitEPSS 5%

    dovecot · dovecotAug 12, 2020

  • Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin.

    HighCVSS 8.2Proof of conceptEPSS 0%

    dovecot · dovecotMar 27, 2026

  • Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with

    HighCVSS 7.5No exploitEPSS 5%

    dovecot · dovecotJan 4, 2021

  • CVE-2017-2669
    31Monitor

    Dovecot before version 2.2.29 is vulnerable to a denial of service.

    HighCVSS 7.5No exploitEPSS 4%

    dovecot · dovecotJun 21, 2018

  • CVE-2009-3235
    31Monitor

    Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve,

    HighCVSS 7.5No exploitEPSS 4%

    dovecot · dovecotSep 17, 2009

  • A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0.

    HighCVSS 7.5No exploitEPSS 3%

    dovecot · dovecotJan 25, 2018

  • The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate wit

    HighCVSS 7.5No exploitEPSS 3%

    dovecot · dovecotApr 24, 2019

  • In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured ch

    HighCVSS 7.5No exploitEPSS 3%

    dovecot · dovecotMay 8, 2019

  • In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the

    HighCVSS 7.5No exploitEPSS 2%

    dovecot · dovecotMay 8, 2019

  • CVE-2008-4577
    31Monitor

    The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass

    HighCVSS 7.5No exploitEPSS 2%

    dovecot · dovecotOct 15, 2008

  • CVE-2019-7524
    31Monitor

    In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can b

    HighCVSS 7.8No exploitEPSS 1%

    dovecot · dovecotMar 28, 2019

  • Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.

    HighCVSS 7.5No exploitEPSS 1%

    dovecot · dovecotMar 27, 2026

  • Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage.

    HighCVSS 7.5No exploitEPSS 1%

    dovecot · dovecotMar 27, 2026

  • ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response.

    HighCVSS 7.5No exploitEPSS 1%

    dovecot · dovecotMar 27, 2026

  • When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fai

    HighCVSS 7.5No exploitEPSS 0%

    dovecot · dovecotMar 27, 2026

  • CVE-2008-1218
    29Monitor

    Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attack

    MediumCVSS 6.8Proof of conceptEPSS 7%

    dovecot · dovecotMar 10, 2008