dovecot records
69 published records for vendor dovecot.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 98.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation11
- CWE-400 Uncontrolled Resource Consumption7
- CWE-264 Permissions, Privileges, and Access Controls6
- CWE-287 Improper Authentication4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-476 NULL Pointer Dereference3
The weakness classes this vendor ships most often: where to look.
CWEAll records
69 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2019-11500No exploit | In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings.dovecot · dovecot · CWE-787 | Critical9.8 | — | 62.6% | Aug 29, 2019 |
45Plan | CVE-2020-7046No exploit | lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrateddovecot · dovecot · CWE-835 | High7.5 | — | 51.3% | Feb 12, 2020 |
37Monitor | CVE-2016-8652No exploit | The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) dovecot · dovecot · CWE-20 | Medium5.9 | — | 48.2% | Feb 16, 2017 |
36Monitor | CVE-2022-30550No exploit | An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20.dovecot · dovecot · CWE-287 | High8.8 | — | 2.2% | Jul 17, 2022 |
36Monitor | CVE-2026-27851No exploit | When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enablidovecot · dovecot · CWE-235 | Critical9.1 | — | 0.6% | May 12, 2026 |
33Monitor | CVE-2017-14461No exploit | A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensidovecot · dovecot · CWE-125 | High7.1 | — | 16.7% | Mar 2, 2018 |
32Monitor | CVE-2020-10957No exploit | In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash indovecot · dovecot · CWE-476 | High7.5 | — | 7.2% | May 18, 2020 |
32Monitor | CVE-2020-12674No exploit | In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.dovecot · dovecot · CWE-125 | High7.5 | — | 6.2% | Aug 12, 2020 |
32Monitor | CVE-2020-12673No exploit | In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.dovecot · dovecot · CWE-125 | High7.5 | — | 6.2% | Aug 12, 2020 |
32Monitor | CVE-2020-12100No exploit | In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resourdovecot · dovecot · CWE-674 | High7.5 | — | 5.3% | Aug 12, 2020 |
32Monitor | CVE-2026-24031Proof of concept | Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin.dovecot · dovecot · CWE-89 | High8.2 | — | 0.4% | Mar 27, 2026 |
31Monitor | CVE-2020-25275No exploit | Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message withdovecot · dovecot · CWE-20 | High7.5 | — | 4.7% | Jan 4, 2021 |
31Monitor | CVE-2017-2669No exploit | Dovecot before version 2.2.29 is vulnerable to a denial of service.dovecot · dovecot · CWE-20 | High7.5 | — | 4.5% | Jun 21, 2018 |
31Monitor | CVE-2009-3235No exploit | Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, dovecot · dovecot · CWE-119 | High7.5 | — | 4.0% | Sep 17, 2009 |
31Monitor | CVE-2017-15132No exploit | A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0.dovecot · dovecot · CWE-400 | High7.5 | — | 3.1% | Jan 25, 2018 |
31Monitor | CVE-2019-10691No exploit | The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate witdovecot · dovecot | High7.5 | — | 2.8% | Apr 24, 2019 |
31Monitor | CVE-2019-11499No exploit | In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured chdovecot · dovecot | High7.5 | — | 2.5% | May 8, 2019 |
31Monitor | CVE-2019-11494No exploit | In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during thedovecot · dovecot · CWE-476 | High7.5 | — | 2.4% | May 8, 2019 |
31Monitor | CVE-2008-4577No exploit | The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypassdovecot · dovecot · CWE-863 | High7.5 | — | 2.3% | Oct 15, 2008 |
31Monitor | CVE-2019-7524No exploit | In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can bdovecot · dovecot · CWE-119 | High7.8 | — | 1.2% | Mar 28, 2019 |
30Monitor | CVE-2026-27858No exploit | Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.dovecot · dovecot · CWE-400 | High7.5 | — | 1.0% | Mar 27, 2026 |
30Monitor | CVE-2026-27857No exploit | Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage.dovecot · dovecot · CWE-400 | High7.5 | — | 0.8% | Mar 27, 2026 |
30Monitor | CVE-2025-59032No exploit | ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response.dovecot · dovecot · CWE-20 | High7.5 | — | 0.7% | Mar 27, 2026 |
30Monitor | CVE-2025-59028No exploit | When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to faidovecot · dovecot · CWE-20 | High7.5 | — | 0.4% | Mar 27, 2026 |
29Monitor | CVE-2008-1218Proof of concept | Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackdovecot · dovecot · CWE-255 | Medium6.8 | — | 7.3% | Mar 10, 2008 |
- CVE-2019-1150058Plan
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings.
CriticalCVSS 9.8No exploitEPSS 63%dovecot · dovecotAug 29, 2019
- CVE-2020-704645Plan
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated
HighCVSS 7.5No exploitEPSS 51%dovecot · dovecotFeb 12, 2020
- CVE-2016-865237Monitor
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash)
MediumCVSS 5.9No exploitEPSS 48%dovecot · dovecotFeb 16, 2017
- CVE-2022-3055036Monitor
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20.
HighCVSS 8.8No exploitEPSS 2%dovecot · dovecotJul 17, 2022
- CVE-2026-2785136Monitor
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabli
CriticalCVSS 9.1No exploitEPSS 1%dovecot · dovecotMay 12, 2026
- CVE-2017-1446133Monitor
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensi
HighCVSS 7.1No exploitEPSS 17%dovecot · dovecotMar 2, 2018
- CVE-2020-1095732Monitor
In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in
HighCVSS 7.5No exploitEPSS 7%dovecot · dovecotMay 18, 2020
- CVE-2020-1267432Monitor
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
HighCVSS 7.5No exploitEPSS 6%dovecot · dovecotAug 12, 2020
- CVE-2020-1267332Monitor
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
HighCVSS 7.5No exploitEPSS 6%dovecot · dovecotAug 12, 2020
- CVE-2020-1210032Monitor
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resour
HighCVSS 7.5No exploitEPSS 5%dovecot · dovecotAug 12, 2020
- CVE-2026-2403132Monitor
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin.
HighCVSS 8.2Proof of conceptEPSS 0%dovecot · dovecotMar 27, 2026
- CVE-2020-2527531Monitor
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with
HighCVSS 7.5No exploitEPSS 5%dovecot · dovecotJan 4, 2021
- CVE-2017-266931Monitor
Dovecot before version 2.2.29 is vulnerable to a denial of service.
HighCVSS 7.5No exploitEPSS 4%dovecot · dovecotJun 21, 2018
- CVE-2009-323531Monitor
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve,
HighCVSS 7.5No exploitEPSS 4%dovecot · dovecotSep 17, 2009
- CVE-2017-1513231Monitor
A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0.
HighCVSS 7.5No exploitEPSS 3%dovecot · dovecotJan 25, 2018
- CVE-2019-1069131Monitor
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate wit
HighCVSS 7.5No exploitEPSS 3%dovecot · dovecotApr 24, 2019
- CVE-2019-1149931Monitor
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured ch
HighCVSS 7.5No exploitEPSS 3%dovecot · dovecotMay 8, 2019
- CVE-2019-1149431Monitor
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the
HighCVSS 7.5No exploitEPSS 2%dovecot · dovecotMay 8, 2019
- CVE-2008-457731Monitor
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass
HighCVSS 7.5No exploitEPSS 2%dovecot · dovecotOct 15, 2008
- CVE-2019-752431Monitor
In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can b
HighCVSS 7.8No exploitEPSS 1%dovecot · dovecotMar 28, 2019
- CVE-2026-2785830Monitor
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.
HighCVSS 7.5No exploitEPSS 1%dovecot · dovecotMar 27, 2026
- CVE-2026-2785730Monitor
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage.
HighCVSS 7.5No exploitEPSS 1%dovecot · dovecotMar 27, 2026
- CVE-2025-5903230Monitor
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response.
HighCVSS 7.5No exploitEPSS 1%dovecot · dovecotMar 27, 2026
- CVE-2025-5902830Monitor
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fai
HighCVSS 7.5No exploitEPSS 0%dovecot · dovecotMar 27, 2026
- CVE-2008-121829Monitor
Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attack
MediumCVSS 6.8Proof of conceptEPSS 7%dovecot · dovecotMar 10, 2008