Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dovecot dovecot vulnerabilities and exploits
(subscribe to this query)
4.8
CVSSv3
CVE-2021-33515
The submission service in Dovecot prior to 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
Dovecot Dovecot
Fedoraproject Fedora 33
Fedoraproject Fedora 34
Debian Debian Linux 10.0
4.3
CVSSv3
CVE-2020-28200
The Sieve engine in Dovecot prior to 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.
Dovecot Dovecot
Fedoraproject Fedora 33
Fedoraproject Fedora 34
3.3
CVSSv3
CVE-2016-4983
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
Dovecot Dovecot -
Opensuse Leap 42.2
Opensuse Leap 42.1
Opensuse Opensuse 13.2
Redhat Enterprise Linux 4.0
Redhat Enterprise Linux 7.0
Redhat Enterprise Linux 6.0
Redhat Enterprise Linux 5.0
NA
CVE-2013-2111
The IMAP functionality in Dovecot prior to 2.2.2 allows remote malicious users to cause a denial of service (infinite loop and CPU consumption) via invalid APPEND parameters.
Dovecot Dovecot
Dovecot Dovecot 2.2
Dovecot Dovecot 2.2.0
NA
CVE-2013-6171
checkpassword-reply in Dovecot prior to 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account infor...
Dovecot Dovecot 2.1
Dovecot Dovecot 2.2.1
Dovecot Dovecot 2.2.3
Dovecot Dovecot 2.1.4
Dovecot Dovecot 2.1.0
Dovecot Dovecot 2.1.3
Dovecot Dovecot 2.0.9
Dovecot Dovecot 2.0
Dovecot Dovecot 2.1.13
Dovecot Dovecot 2.1.14
Dovecot Dovecot 2.1.6
Dovecot Dovecot 2.2
Dovecot Dovecot 2.1.10
Dovecot Dovecot 2.0.14
Dovecot Dovecot 2.0.7
Dovecot Dovecot 2.0.12
Dovecot Dovecot 2.0.4
Dovecot Dovecot 2.1.12
Dovecot Dovecot 2.0.2
Dovecot Dovecot 2.2.4
Dovecot Dovecot 2.0.1
Dovecot Dovecot 2.2.0
NA
CVE-2011-4318
Dovecot 2.0.x prior to 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle mali...
Dovecot Dovecot 2.0.9
Dovecot Dovecot 2.0.14
Dovecot Dovecot 2.0.7
Dovecot Dovecot 2.0.12
Dovecot Dovecot 2.0.4
Dovecot Dovecot 2.0.2
Dovecot Dovecot 2.0.1
Dovecot Dovecot 2.0.10
Dovecot Dovecot 2.0.11
Dovecot Dovecot 2.0.13
Dovecot Dovecot 2.0.8
Dovecot Dovecot 2.0.3
Dovecot Dovecot 2.0.0
Dovecot Dovecot 2.0.15
Dovecot Dovecot 2.0.5
Dovecot Dovecot 2.0.6
NA
CVE-2011-2166
script-login in Dovecot 2.0.x prior to 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
Dovecot Dovecot 2.0.9
Dovecot Dovecot 2.0.7
Dovecot Dovecot 2.0.12
Dovecot Dovecot 2.0.4
Dovecot Dovecot 2.0.2
Dovecot Dovecot 2.0.1
Dovecot Dovecot 2.0.10
Dovecot Dovecot 2.0.11
Dovecot Dovecot 2.0.8
Dovecot Dovecot 2.0.3
Dovecot Dovecot 2.0.0
Dovecot Dovecot 2.0.5
Dovecot Dovecot 2.0.6
NA
CVE-2011-2167
script-login in Dovecot 2.0.x prior to 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
Dovecot Dovecot 2.0.9
Dovecot Dovecot 2.0.7
Dovecot Dovecot 2.0.12
Dovecot Dovecot 2.0.4
Dovecot Dovecot 2.0.2
Dovecot Dovecot 2.0.1
Dovecot Dovecot 2.0.10
Dovecot Dovecot 2.0.11
Dovecot Dovecot 2.0.8
Dovecot Dovecot 2.0.3
Dovecot Dovecot 2.0.0
Dovecot Dovecot 2.0.5
Dovecot Dovecot 2.0.6
NA
CVE-2011-1929
lib-mail/message-header-parser.c in Dovecot 1.2.x prior to 1.2.17 and 2.0.x prior to 2.0.13 does not properly handle '\0' characters in header names, which allows remote malicious users to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-ma...
Dovecot Dovecot 1.2.2
Dovecot Dovecot 1.2.7
Dovecot Dovecot 1.2.4
Dovecot Dovecot 1.2.9
Dovecot Dovecot 1.2.11
Dovecot Dovecot 1.2.1
Dovecot Dovecot 1.2.13
Dovecot Dovecot 1.2.8
Dovecot Dovecot 1.2.16
Dovecot Dovecot 1.2.6
Dovecot Dovecot 1.2.5
Dovecot Dovecot 1.2.10
Dovecot Dovecot 1.2.14
Dovecot Dovecot 1.2.3
Dovecot Dovecot 1.2.0
Dovecot Dovecot 1.2.15
Dovecot Dovecot 1.2.12
Dovecot Dovecot 2.0.9
Dovecot Dovecot 2.0
Dovecot Dovecot 2.0.7
Dovecot Dovecot 2.0.12
Dovecot Dovecot 2.0.4
NA
CVE-2010-4011
Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a...
Apple Mac Os X Server 10.6.5
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »