Записи dovecot
69 опубликованных записей вендора dovecot.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 98,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation11
- CWE-400 Uncontrolled Resource Consumption7
- CWE-264 Permissions, Privileges, and Access Controls6
- CWE-287 Improper Authentication4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-476 NULL Pointer Dereference3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
69 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2019-11500Эксплойта нет | In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings.dovecot · dovecot · CWE-787 | Критическая9,8 | — | 62,6 % | 29 авг. 2019 г. |
45В плане | CVE-2020-7046Эксплойта нет | lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrateddovecot · dovecot · CWE-835 | Высокая7,5 | — | 51,3 % | 12 февр. 2020 г. |
37Наблюдать | CVE-2016-8652Эксплойта нет | The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) dovecot · dovecot · CWE-20 | Средняя5,9 | — | 48,2 % | 16 февр. 2017 г. |
36Наблюдать | CVE-2022-30550Эксплойта нет | An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20.dovecot · dovecot · CWE-287 | Высокая8,8 | — | 2,2 % | 17 июл. 2022 г. |
36Наблюдать | CVE-2026-27851Эксплойта нет | When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enablidovecot · dovecot · CWE-235 | Критическая9,1 | — | 0,6 % | 12 мая 2026 г. |
33Наблюдать | CVE-2017-14461Эксплойта нет | A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensidovecot · dovecot · CWE-125 | Высокая7,1 | — | 16,7 % | 2 мар. 2018 г. |
32Наблюдать | CVE-2020-10957Эксплойта нет | In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash indovecot · dovecot · CWE-476 | Высокая7,5 | — | 7,2 % | 18 мая 2020 г. |
32Наблюдать | CVE-2020-12674Эксплойта нет | In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.dovecot · dovecot · CWE-125 | Высокая7,5 | — | 6,2 % | 12 авг. 2020 г. |
32Наблюдать | CVE-2020-12673Эксплойта нет | In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.dovecot · dovecot · CWE-125 | Высокая7,5 | — | 6,2 % | 12 авг. 2020 г. |
32Наблюдать | CVE-2020-12100Эксплойта нет | In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resourdovecot · dovecot · CWE-674 | Высокая7,5 | — | 5,3 % | 12 авг. 2020 г. |
32Наблюдать | CVE-2026-24031Proof of concept | Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin.dovecot · dovecot · CWE-89 | Высокая8,2 | — | 0,4 % | 27 мар. 2026 г. |
31Наблюдать | CVE-2020-25275Эксплойта нет | Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message withdovecot · dovecot · CWE-20 | Высокая7,5 | — | 4,7 % | 4 янв. 2021 г. |
31Наблюдать | CVE-2017-2669Эксплойта нет | Dovecot before version 2.2.29 is vulnerable to a denial of service.dovecot · dovecot · CWE-20 | Высокая7,5 | — | 4,5 % | 21 июн. 2018 г. |
31Наблюдать | CVE-2009-3235Эксплойта нет | Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, dovecot · dovecot · CWE-119 | Высокая7,5 | — | 4,0 % | 17 сент. 2009 г. |
31Наблюдать | CVE-2017-15132Эксплойта нет | A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0.dovecot · dovecot · CWE-400 | Высокая7,5 | — | 3,1 % | 25 янв. 2018 г. |
31Наблюдать | CVE-2019-10691Эксплойта нет | The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate witdovecot · dovecot | Высокая7,5 | — | 2,8 % | 24 апр. 2019 г. |
31Наблюдать | CVE-2019-11499Эксплойта нет | In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured chdovecot · dovecot | Высокая7,5 | — | 2,5 % | 8 мая 2019 г. |
31Наблюдать | CVE-2019-11494Эксплойта нет | In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during thedovecot · dovecot · CWE-476 | Высокая7,5 | — | 2,4 % | 8 мая 2019 г. |
31Наблюдать | CVE-2008-4577Эксплойта нет | The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypassdovecot · dovecot · CWE-863 | Высокая7,5 | — | 2,3 % | 15 окт. 2008 г. |
31Наблюдать | CVE-2019-7524Эксплойта нет | In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can bdovecot · dovecot · CWE-119 | Высокая7,8 | — | 1,2 % | 28 мар. 2019 г. |
30Наблюдать | CVE-2026-27858Эксплойта нет | Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.dovecot · dovecot · CWE-400 | Высокая7,5 | — | 1,0 % | 27 мар. 2026 г. |
30Наблюдать | CVE-2026-27857Эксплойта нет | Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage.dovecot · dovecot · CWE-400 | Высокая7,5 | — | 0,8 % | 27 мар. 2026 г. |
30Наблюдать | CVE-2025-59032Эксплойта нет | ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response.dovecot · dovecot · CWE-20 | Высокая7,5 | — | 0,7 % | 27 мар. 2026 г. |
30Наблюдать | CVE-2025-59028Эксплойта нет | When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to faidovecot · dovecot · CWE-20 | Высокая7,5 | — | 0,4 % | 27 мар. 2026 г. |
29Наблюдать | CVE-2008-1218Proof of concept | Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackdovecot · dovecot · CWE-255 | Средняя6,8 | — | 7,3 % | 10 мар. 2008 г. |
- CVE-2019-1150058В плане
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings.
КритическаяCVSS 9,8Эксплойта нетEPSS 63 %dovecot · dovecot29 авг. 2019 г.
- CVE-2020-704645В плане
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated
ВысокаяCVSS 7,5Эксплойта нетEPSS 51 %dovecot · dovecot12 февр. 2020 г.
- CVE-2016-865237Наблюдать
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash)
СредняяCVSS 5,9Эксплойта нетEPSS 48 %dovecot · dovecot16 февр. 2017 г.
- CVE-2022-3055036Наблюдать
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dovecot · dovecot17 июл. 2022 г.
- CVE-2026-2785136Наблюдать
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabli
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %dovecot · dovecot12 мая 2026 г.
- CVE-2017-1446133Наблюдать
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensi
ВысокаяCVSS 7,1Эксплойта нетEPSS 17 %dovecot · dovecot2 мар. 2018 г.
- CVE-2020-1095732Наблюдать
In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %dovecot · dovecot18 мая 2020 г.
- CVE-2020-1267432Наблюдать
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %dovecot · dovecot12 авг. 2020 г.
- CVE-2020-1267332Наблюдать
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %dovecot · dovecot12 авг. 2020 г.
- CVE-2020-1210032Наблюдать
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resour
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %dovecot · dovecot12 авг. 2020 г.
- CVE-2026-2403132Наблюдать
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin.
ВысокаяCVSS 8,2Proof of conceptEPSS 0 %dovecot · dovecot27 мар. 2026 г.
- CVE-2020-2527531Наблюдать
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %dovecot · dovecot4 янв. 2021 г.
- CVE-2017-266931Наблюдать
Dovecot before version 2.2.29 is vulnerable to a denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %dovecot · dovecot21 июн. 2018 г.
- CVE-2009-323531Наблюдать
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve,
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %dovecot · dovecot17 сент. 2009 г.
- CVE-2017-1513231Наблюдать
A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %dovecot · dovecot25 янв. 2018 г.
- CVE-2019-1069131Наблюдать
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate wit
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %dovecot · dovecot24 апр. 2019 г.
- CVE-2019-1149931Наблюдать
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured ch
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %dovecot · dovecot8 мая 2019 г.
- CVE-2019-1149431Наблюдать
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %dovecot · dovecot8 мая 2019 г.
- CVE-2008-457731Наблюдать
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %dovecot · dovecot15 окт. 2008 г.
- CVE-2019-752431Наблюдать
In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can b
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %dovecot · dovecot28 мар. 2019 г.
- CVE-2026-2785830Наблюдать
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dovecot · dovecot27 мар. 2026 г.
- CVE-2026-2785730Наблюдать
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dovecot · dovecot27 мар. 2026 г.
- CVE-2025-5903230Наблюдать
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dovecot · dovecot27 мар. 2026 г.
- CVE-2025-5902830Наблюдать
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fai
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %dovecot · dovecot27 мар. 2026 г.
- CVE-2008-121829Наблюдать
Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attack
СредняяCVSS 6,8Proof of conceptEPSS 7 %dovecot · dovecot10 мар. 2008 г.