Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dovecot dovecot vulnerabilities and exploits
(subscribe to this query)
445
VMScore
CVE-2020-10958
In Dovecot prior to 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.
Dovecot Dovecot
445
VMScore
CVE-2020-7957
The IMAP and LMTP components in Dovecot 2.3.9 prior to 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the recipient cannot read all of their messages.
Dovecot Dovecot
Fedoraproject Fedora 30
Fedoraproject Fedora 31
445
VMScore
CVE-2019-19722
In Dovecot prior to 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
Dovecot Dovecot
Fedoraproject Fedora 30
Fedoraproject Fedora 31
445
VMScore
CVE-2019-11494
In the IMAP Server in Dovecot 2.3.3 up to and including 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.
Dovecot Dovecot
Fedoraproject Fedora 29
Fedoraproject Fedora 30
Opensuse Leap 15.0
Opensuse Leap 15.1
445
VMScore
CVE-2019-11499
In the IMAP Server in Dovecot 2.3.3 up to and including 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.
Dovecot Dovecot
Fedoraproject Fedora 29
Fedoraproject Fedora 30
Opensuse Leap 15.0
Opensuse Leap 15.1
445
VMScore
CVE-2019-10691
The JSON encoder in Dovecot prior to 2.3.5.2 allows malicious users to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
Dovecot Dovecot
Opensuse Leap 15.0
445
VMScore
CVE-2017-2669
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variab...
Dovecot Dovecot
Debian Debian Linux 8.0
445
VMScore
CVE-2017-15132
A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the pr...
Dovecot Dovecot
Dovecot Dovecot 2.3.0
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Debian Debian Linux 9.0
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 17.10
445
VMScore
CVE-2013-2111
The IMAP functionality in Dovecot prior to 2.2.2 allows remote malicious users to cause a denial of service (infinite loop and CPU consumption) via invalid APPEND parameters.
Dovecot Dovecot
Dovecot Dovecot 2.2
Dovecot Dovecot 2.2.0
445
VMScore
CVE-2011-1929
lib-mail/message-header-parser.c in Dovecot 1.2.x prior to 1.2.17 and 2.0.x prior to 2.0.13 does not properly handle '\0' characters in header names, which allows remote malicious users to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-ma...
Dovecot Dovecot 1.2.2
Dovecot Dovecot 1.2.7
Dovecot Dovecot 1.2.4
Dovecot Dovecot 1.2.9
Dovecot Dovecot 1.2.11
Dovecot Dovecot 1.2.1
Dovecot Dovecot 1.2.13
Dovecot Dovecot 1.2.8
Dovecot Dovecot 1.2.16
Dovecot Dovecot 1.2.6
Dovecot Dovecot 1.2.5
Dovecot Dovecot 1.2.10
Dovecot Dovecot 1.2.14
Dovecot Dovecot 1.2.3
Dovecot Dovecot 1.2.0
Dovecot Dovecot 1.2.15
Dovecot Dovecot 1.2.12
Dovecot Dovecot 2.0.9
Dovecot Dovecot 2.0
Dovecot Dovecot 2.0.7
Dovecot Dovecot 2.0.12
Dovecot Dovecot 2.0.4
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5834
CVE-2024-30100
CVE-2024-4577
physical
dos
CVE-2024-30099
CVE-2024-27801
CVE-2024-32146
logic flaw
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »