Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-40016 Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of … Dovecot 2.4.4 / 3.1.5+ Fix from $1,6002026-05-12 MEDIUM 5.3 CVE-2026-33603 Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is… Dovecot 2.4.4 / 3.1.5+ Fix from $1,6002026-05-12 CRITICAL 9.1 CVE-2026-27851 When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe… Dovecot 2.4.4 / 3.1.5+ Fix from $2,3002026-05-12 HIGH 7.5 CVE-2026-27858 Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can for… Dovecot 2.3.22.1 / 2.4.3+ Fix from $1,9502026-03-27 MEDIUM 5.3 CVE-2026-27859 A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail… Dovecot 2.4.3 / 3.0.5+ Fix from $1,6002026-03-27 MEDIUM 5.3 CVE-2026-27860 If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing… Dovecot 2.4.3 / 3.1.4+ Fix from $1,6002026-03-27 HIGH 8.2 CVE-2026-24031 Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for… Dovecot 2.4.3 / 3.1.4+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-27857 Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnec… Dovecot 2.3.22.1 / 2.4.3+ Fix from $1,9502026-03-27 MEDIUM 5.9 CVE-2026-27855 Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, the… Dovecot 2.4.3+ Fix from $1,6002026-03-27 MEDIUM 5.9 CVE-2026-27856 Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the conf… Dovecot 2.3.22.1 / 2.4.3+ Fix from $1,6002026-03-27 MEDIUM 5.3 CVE-2026-0394 When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowe… Dovecot 2.4.0 / 3.1.0+ Fix from $1,6002026-03-27 HIGH 7.5 CVE-2025-59028 When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invali… Dovecot 2.4.3 / 3.1.2+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2025-59032 ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, makin… Dovecot 2.4.3 / 3.1.3+ Fix from $1,9502026-03-27 MEDIUM 5.3 CVE-2020-10967EPSS 8% In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart. Dovecot 2.3.10.1+ Fix from $1,6002020-05-18 HIGH 7.5 CVE-2020-10957EPSS 7% In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submissi… Dovecot 2.3.10.1+ Fix from $1,9502020-05-18 MEDIUM 5.3 CVE-2020-10958EPSS 6% In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and … Dovecot 2.3.10.1+ Fix from $1,6002020-05-18 HIGH 7.5 CVE-2019-10691 The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an inva… Dovecot 2.3.5.2+ Fix from $1,9502019-04-24 MEDIUM 5.9 CVE-2016-8652EPSS 48% The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborti… Dovecot after 2.2.27 Fix from $1,6002017-02-17 MEDIUM 5.0 CVE-2013-2111 The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via invalid A… Dovecot after 2.2.1 Fix from $1,6002014-05-27 MEDIUM 5.0 CVE-2014-3430 Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attac… Dovecot Patch available Fix from $1,6002014-05-14 MEDIUM 5.8 CVE-2013-6171 checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentica… Dovecot after 2.2.6 Fix from $1,6002013-12-09 MEDIUM 5.8 CVE-2011-4318 Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server ho… Dovecot Mitigation only Fix from $1,6002013-03-07 MEDIUM 6.5 CVE-2011-2166 script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users t… Dovecot Patch available Fix from $1,6002011-05-24 MEDIUM 6.5 CVE-2011-2167 script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct… Dovecot Patch available Fix from $1,6002011-05-24 MEDIUM 5.0 CVE-2011-1929 lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, whi… Dovecot Patch available Fix from $1,6002011-05-24 MEDIUM 5.5 CVE-2010-3706 plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permission… Dovecot Mitigation only Fix from $1,6002010-10-06 MEDIUM 5.5 CVE-2010-3707 plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permission… Dovecot Mitigation only Fix from $1,6002010-10-06 MEDIUM 6.4 CVE-2010-3304 The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote at… Dovecot Patch available Fix from $1,6002010-09-24 MEDIUM 5.0 CVE-2010-0745 Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in a… Dovecot Patch available Fix from $1,6002010-05-20 MEDIUM 5.5 CVE-2009-3897 Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbi… Dovecot 1.2.8+ Fix from $1,6002009-11-24