VYPR

Dovecot

by Dovecot (software)

Source repositories

CVEs (76)

  • CVE-2019-11500CriAug 29, 2019
    risk 0.69cvss 9.8epss 0.63

    In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

  • CVE-2022-30550HigJul 17, 2022
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly…

  • CVE-2020-7046HigFeb 12, 2020
    risk 0.53cvss 7.5epss 0.51

    lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.

  • CVE-2019-7524HigMar 28, 2019
    risk 0.50cvss 8.8epss 0.01

    In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and pop3-uidl components.

  • CVE-2019-3814HigMar 27, 2019
    risk 0.50cvss 7.7epss 0.02

    It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.

  • CVE-2024-23185HigSep 10, 2024
    risk 0.49cvss 7.5epss 0.01

    Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The…

  • CVE-2021-29157HigJun 28, 2021
    risk 0.49cvss 7.5epss 0.00

    Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.

  • CVE-2020-25275HigJan 4, 2021
    risk 0.49cvss 7.5epss 0.05

    Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.

  • CVE-2020-12674HigAug 12, 2020
    risk 0.49cvss 7.5epss 0.06

    In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.

  • CVE-2020-12673HigAug 12, 2020
    risk 0.49cvss 7.5epss 0.06

    In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.

  • CVE-2020-12100HigAug 12, 2020
    risk 0.49cvss 7.5epss 0.05

    In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.

  • CVE-2020-10957HigMay 18, 2020
    risk 0.49cvss 7.5epss 0.07

    In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

  • CVE-2019-11494HigMay 8, 2019
    risk 0.49cvss 7.5epss 0.02

    In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.

  • CVE-2019-11499HigMay 8, 2019
    risk 0.49cvss 7.5epss 0.03

    In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.

  • CVE-2019-10691HigApr 24, 2019
    risk 0.49cvss 7.5epss 0.03

    The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.

  • CVE-2008-4577HigOct 15, 2008
    risk 0.49cvss 7.5epss 0.02

    The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.

  • CVE-2026-27851HigMay 12, 2026
    risk 0.48cvss 7.4epss 0.00

    When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on…

  • CVE-2026-33603MedMay 12, 2026
    risk 0.44cvss 6.8epss 0.00

    Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications…

  • CVE-2020-24386MedJan 4, 2021
    risk 0.44cvss 6.8epss 0.03

    An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

  • CVE-2026-24031HigMar 27, 2026
    risk 0.43cvss 7.7epss 0.00

    Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No…

Page 1 of 4

VYPR — Vulnerability Intelligence