Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-40016
Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of …
Dovecot
2.4.4 / 3.1.5+
MEDIUM 5.3
CVE-2026-33603
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is…
Dovecot
2.4.4 / 3.1.5+
CRITICAL 9.1
CVE-2026-27851
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe…
Dovecot
2.4.4 / 3.1.5+
HIGH 7.5
CVE-2026-27858
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.
Attacker can for…
Dovecot
2.3.22.1 / 2.4.3+
MEDIUM 5.3
CVE-2026-27859
A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail…
Dovecot
2.4.3 / 3.0.5+
MEDIUM 5.3
CVE-2026-27860
If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing…
Dovecot
2.4.3 / 3.1.4+
HIGH 8.2
CVE-2026-24031
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for…
Dovecot
2.4.3 / 3.1.4+
HIGH 7.5
CVE-2026-27857
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnec…
Dovecot
2.3.22.1 / 2.4.3+
MEDIUM 5.9
CVE-2026-27855
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, the…
Dovecot
2.4.3+
MEDIUM 5.9
CVE-2026-27856
Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the conf…
Dovecot
2.3.22.1 / 2.4.3+
MEDIUM 5.3
CVE-2026-0394
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowe…
Dovecot
2.4.0 / 3.1.0+
HIGH 7.5
CVE-2025-59028
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invali…
Dovecot
2.4.3 / 3.1.2+
HIGH 7.5
CVE-2025-59032
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, makin…
Dovecot
2.4.3 / 3.1.3+
MEDIUM 5.3
CVE-2020-10967EPSS 8%
In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.
Dovecot
2.3.10.1+
HIGH 7.5
CVE-2020-10957EPSS 7%
In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submissi…
Dovecot
2.3.10.1+
MEDIUM 5.3
CVE-2020-10958EPSS 6%
In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and …
Dovecot
2.3.10.1+
HIGH 7.5
CVE-2019-10691
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an inva…
Dovecot
2.3.5.2+
MEDIUM 5.9
CVE-2016-8652EPSS 48%
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborti…
Dovecot
after 2.2.27
MEDIUM 5.0
CVE-2013-2111
The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via invalid A…
Dovecot
after 2.2.1
MEDIUM 5.0
CVE-2014-3430
Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attac…
Dovecot
Patch available
MEDIUM 5.8
CVE-2013-6171
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentica…
Dovecot
after 2.2.6
MEDIUM 5.8
CVE-2011-4318
Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server ho…
Dovecot
Mitigation only
MEDIUM 6.5
CVE-2011-2166
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users t…
Dovecot
Patch available
MEDIUM 6.5
CVE-2011-2167
script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct…
Dovecot
Patch available
MEDIUM 5.0
CVE-2011-1929
lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, whi…
Dovecot
Patch available
MEDIUM 5.5
CVE-2010-3706
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permission…
Dovecot
Mitigation only
MEDIUM 5.5
CVE-2010-3707
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permission…
Dovecot
Mitigation only
MEDIUM 6.4
CVE-2010-3304
The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote at…
Dovecot
Patch available
MEDIUM 5.0
CVE-2010-0745
Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in a…
Dovecot
Patch available
MEDIUM 5.5
CVE-2009-3897
Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbi…
Dovecot
1.2.8+