cbcvebase.

Debian Dovecot vulnerabilities

65 known vulnerabilities affecting debian/dovecot.

Total CVEs
65
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH17MEDIUM29LOW18

Vulnerabilities

Page 2 of 4
CVE-2017-2669P3LOWCVSS 3.7fixed in dovecot 1:2.2.27-3 (bookworm)2017
CVE-2017-2669 [LOW] CVE-2017-2669: dovecot - Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' ... Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or exces
debian
CVE-2020-24386P3MEDIUMCVSS 6.8fixed in dovecot 1:2.3.13+dfsg1-1 (bookworm)2020
CVE-2020-24386 [MEDIUM] CVE-2020-24386: dovecot - An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authent... An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure). Scope: local bookworm: resolved (fixed in 1:2.3.13+dfsg1-1) bullseye: resolved (fixed in 1:2.3.13+dfsg1-1) forky: resolved (fixed in 1:2
debian
CVE-2020-12100P3HIGHCVSS 7.5fixed in dovecot 1:2.3.11.3+dfsg1-1 (bookworm)2020
CVE-2020-12100 [HIGH] CVE-2020-12100: dovecot - In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda ... In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts. Scope: local bookworm: resolved (fixed in 1:2.3.11.3+dfsg1-1) bullseye: resolved (fixed in 1:2.3.11.3+dfsg1-1) forky: resolved (fixed in 1:2.3.11.3+dfsg
debian
CVE-2017-15132P3HIGHCVSS 7.5fixed in dovecot 1:2.2.34-1 (bookworm)2017
CVE-2017-15132 [HIGH] CVE-2017-15132: dovecot - A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authent... A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion. Scope: local bookworm: resolved (fixed in 1:2.2.34-1
debian
CVE-2019-10691P3HIGHCVSS 7.5fixed in dovecot 1:2.3.4.1-4 (bookworm)2019
CVE-2019-10691 [HIGH] CVE-2019-10691: dovecot - The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash ... The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username. Scope: local bookworm: resolved (fixed in 1:2.3.4.1-4) bullseye: resolved (fixed in 1:2.3.4.1-4) forky: resolved (fixed in 1:2.3.4.1-4) sid: resolved (fixed in 1:2.3.4.1-4) trixie: re
debian
CVE-2020-10967P3MEDIUMCVSS 5.3fixed in dovecot 1:2.3.10.1+dfsg1-1 (bookworm)2020
CVE-2020-10967 [MEDIUM] CVE-2020-10967: dovecot - In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp ... In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart. Scope: local bookworm: resolved (fixed in 1:2.3.10.1+dfsg1-1) bullseye: resolved (fixed in 1:2.3.10.1+dfsg1-1) forky: resolved (fixed in 1:2.3.10.1+dfsg1-1) sid: resolved (fixed in 1:2.3.10.1+dfsg1-1) trixie: resolved (fixe
debian
CVE-2026-27855P3MEDIUMCVSS 6.8fixed in dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm)2026
CVE-2026-27855 [MEDIUM] CVE-2026-27855: dovecot - Dovecot OTP authentication is vulnerable to replay attack under specific conditi... Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol.
debian
CVE-2019-3814P3HIGHCVSS 7.7fixed in dovecot 1:2.3.4.1-1 (bookworm)2019
CVE-2019-3814 [HIGH] CVE-2019-3814: dovecot - It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly ... It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users. Scope: local bookworm: resolved (fixed in 1:2.3.4.1-1) bullseye: resolved (fixed in 1:2.3.4.1-1) forky: resolved (fixed
debian
CVE-2008-4577P3LOWCVSS 7.5fixed in dovecot 1:1.0.15-2.2 (bookworm)2008
CVE-2008-4577 [HIGH] CVE-2008-4577: dovecot - The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they ... The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions. Scope: local bookworm: resolved (fixed in 1:1.0.15-2.2) bullseye: resolved (fixed in 1:1.0.15-2.2) forky: resolved (fixed in 1:1.0.15-2.2) sid: resolved (fixed in 1:1.0.15-2.2) trixie: resolved (fixe
debian
CVE-2026-27856P3HIGHCVSS 7.4fixed in dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm)2026
CVE-2026-27856 [HIGH] CVE-2026-27856: dovecot - Doveadm credentials are verified using direct comparison which is susceptible to... Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, install fixed version. No publicly available exploits are known. Scope
debian
CVE-2009-3235P3MEDIUMCVSS 4.4fixed in dovecot 1:1.2.1-1 (bookworm)2009
CVE-2009-3235 [MEDIUM] CVE-2009-3235: dovecot - Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before ... Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different
debian
CVE-2020-10958P4MEDIUMCVSS 5.3fixed in dovecot 1:2.3.10.1+dfsg1-1 (bookworm)2020
CVE-2020-10958 [MEDIUM] CVE-2020-10958: dovecot - In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthentica... In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command. Scope: local bookworm: resolved (fixed in 1:2.3.10.1+dfsg1-1) bullseye: resolved (fixed in 1:2.3.10.1+dfsg1-1) forky: resolved (fixed in
debian
CVE-2010-3304P4MEDIUMCVSS 6.4fixed in dovecot 1.2.13-1 (bookworm)2010
CVE-2010-3304 [MEDIUM] CVE-2010-3304: dovecot - The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly cre... The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs. Scope: local bookworm: resolved (fixed in 1.2.13-1) bullseye: resolved (fixed in 1.2.13-1) forky: resolved (fixed in 1.2.13-1) sid: resolved (fixed in 1.2.13-1)
debian
CVE-2008-5301P4MEDIUMCVSS 6.4fixed in dovecot 1:1.0.15-2.3 (bookworm)2008
CVE-2008-5301 [MEDIUM] CVE-2008-5301: dovecot - Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1... Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name. Scope: local bookworm: resolved (fixed in 1:1.0.15-2.3) bullseye: resolved (fixed in 1:1.0.15-2.3) forky: resolved (fixed in 1:1.0.15-2.3) sid: resolved (fixed in
debian
CVE-2026-0394P4MEDIUMCVSS 5.3fixed in dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm)2026
CVE-2026-0394 [MEDIUM] CVE-2026-0394: dovecot - When dovecot has been configured to use per-domain passwd files, and they are pl... When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path which ends with passwd). If this file contains passwords, it can be
debian
CVE-2017-15130P4MEDIUMCVSS 5.9fixed in dovecot 1:2.2.34-1 (bookworm)2017
CVE-2017-15130 [MEDIUM] CVE-2017-15130: dovecot - A denial of service flaw was found in dovecot before 2.2.34. An attacker able to... A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart. Scope: local bookworm: resolved (fixed in 1:2.2.34-1) bullseye: resolved (fixed in 1:2.2.34-1) forky: resolved (fixed in 1:2.2.34-1) sid: resolve
debian
CVE-2026-27860P4LOWCVSS 3.7fixed in dovecot 1:2.4.3+dfsg1-1 (sid)2026
CVE-2026-27860 [LOW] CVE-2026-27860: dovecot - If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter ... If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out auth_username_chars, or install fixed version. No publicly available exploits are known. Scope: local bookworm: resolved bullseye: resolved forky: open
debian
CVE-2007-6598P4LOWCVSS 6.8fixed in dovecot 1:1.0.10-1 (bookworm)2007
CVE-2007-6598 [MEDIUM] CVE-2007-6598: dovecot - Dovecot before 1.0.10, with certain configuration options including use of %vari... Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password. Scope: local bookworm: resolved (fixed in 1:1.0.10-1) bullseye: resolved (fixed in 1:1.0.10-1) forky: resolved (fixed in 1:1.0.10-1)
debian
CVE-2011-2166P4LOWCVSS 6.5fixed in dovecot 1:2.0.13-1 (bookworm)2011
CVE-2011-2166 [MEDIUM] CVE-2011-2166: dovecot - script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group c... script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script. Scope: local bookworm: resolved (fixed in 1:2.0.13-1) bullseye: resolved (fixed in 1:2.0.13-1) forky: resolved (fixed in 1:2.0.13-1) sid: resolved (fixed in
debian
CVE-2014-3430P4LOWCVSS 5.0fixed in dovecot 1:2.2.13~rc1-1 (bookworm)2014
CVE-2014-3430 [MEDIUM] CVE-2014-3430: dovecot - Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.... Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection. Scope: local bookworm: resolved (fixed in 1:2.2.13~rc1-1) bullseye: resolved (fixed in 1:2.2.13~r
debian
Debian Dovecot vulnerabilities | cvebase