cbcvebase.

Debian Dovecot vulnerabilities

65 known vulnerabilities affecting debian/dovecot.

Total CVEs
65
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH17MEDIUM29LOW18

Vulnerabilities

Page 3 of 4
CVE-2011-2167P4LOWCVSS 6.5fixed in dovecot 1:2.0.13-1 (bookworm)2011
CVE-2011-2167 [MEDIUM] CVE-2011-2167: dovecot - script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configura... script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script. Scope: local bookworm: resolved (fixed in 1:2.0.13-1) bullseye: resolved (fixed in 1:2.0.13-1) forky: resolved (fixed in 1:2.0.13-1) sid: resolved (fixed in 1:2.0.13-
debian
CVE-2010-3707P4MEDIUMCVSS 5.5fixed in dovecot 1:1.2.15-1 (bookworm)2010
CVE-2010-3707 [MEDIUM] CVE-2010-3707: dovecot - plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before ... plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allo
debian
CVE-2013-6171P4LOWCVSS 5.8fixed in dovecot 1:2.2.9-1 (bookworm)2013
CVE-2013-6171 [MEDIUM] CVE-2013-6171: dovecot - checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user... checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server. Scope: local bookworm: resolved (fixed
debian
CVE-2010-3706P4MEDIUMCVSS 5.5fixed in dovecot 1:1.2.15-1 (bookworm)2010
CVE-2010-3706 [MEDIUM] CVE-2010-3706: dovecot - plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before ... plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users
debian
CVE-2021-33515P4MEDIUMCVSS 4.8fixed in dovecot 1:2.3.13+dfsg1-2 (bookworm)2021
CVE-2021-33515 [MEDIUM] CVE-2021-33515: dovecot - The submission service in Dovecot before 2.3.15 allows STARTTLS command injectio... The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address. Scope: local bookworm: resolved (fixed in 1:2.3.13+dfsg1-2) bullseye: resolved (fixed in 1:2.3.13+dfsg1-2) forky: resolved (fixed in 1:2.3.13+dfsg1-2) sid: resolved (fixed in 1:2.3.13+dfsg1-2) tri
debian
CVE-2024-23184P4MEDIUMCVSS 5.0fixed in dovecot 1:2.3.19.1+dfsg1-2.1+deb12u1 (bookworm)2024
CVE-2024-23184 [MEDIUM] CVE-2024-23184: dovecot - Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes exces... Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attac
debian
CVE-2021-29157P4HIGHCVSS 7.5fixed in dovecot 1:2.3.13+dfsg1-2 (bookworm)2021
CVE-2021-29157 [HIGH] CVE-2021-29157: dovecot - Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the ... Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver. Scope: local bookworm: resolved (fixed in 1:2.3.13+dfsg1-2) bullseye: resolved (fixed in 1:2.
debian
CVE-2026-27859P4MEDIUMCVSS 5.3fixed in dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm)2026
CVE-2026-27859 [MEDIUM] CVE-2026-27859: dovecot - A mail message containing excessive amount of RFC 2231 MIME parameters causes LM... A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CPU time. Use MTA capabilities to limit RFC 2231 MIME parameters in mail messages, or upgrade to fixed version where the processing is limited. No publicly available explo
debian
CVE-2007-2231P4MEDIUMCVSS 4.3fixed in dovecot 1.0.rc29-1 (bookworm)2007
CVE-2007-2231 [MEDIUM] CVE-2007-2231: dovecot - Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before... Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name. Scope: local bookworm: resolved (fixed in 1.0.rc29-1) bullseye: resolved (fixed in 1.0.rc29-1) forky: resolved (fixed in
debian
CVE-2008-4578P4LOWCVSS 5.0fixed in dovecot 1:1.1.9-1 (bookworm)2008
CVE-2008-4578 [MEDIUM] CVE-2008-4578: dovecot - The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended acces... The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes. Scope: local bookworm: resolved (fixed in 1:1.1.9-1) bullseye: resolved (fixed in 1:1.1.9-1) forky: resolved (fixed in 1:1.1.9-1) sid: resolved (fixed in 1:1.1.9-1) trixie: resolved (fixed in 1:1
debian
CVE-2015-3420P4MEDIUMCVSS 5.9fixed in dovecot 1:2.2.13-12 (bookworm)2015
CVE-2015-3420 [MEDIUM] CVE-2015-3420: dovecot - The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disable... The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures. Scope: local bookworm: resolved (fixed in 1:2.2.13-12) bullseye: resolved (fixed in 1:2.2.13-12) forky: resolved (fixed in 1:2.2.13-12) sid: resolved (fixed in 1:2.2.13
debian
CVE-2007-4211P4LOWCVSS 6.0fixed in dovecot 1:1.0.3-2 (bookworm)2007
CVE-2007-4211 [MEDIUM] CVE-2007-4211: dovecot - The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with th... The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command. Scope: local bookworm: resolved (fixed in 1:1.0.3-2) bullseye: resolved (fixed in 1:1.0.3-2) forky: resolved (fixed in 1:1.0.3-2) sid: resolved (fixed in 1:1.0.3-2) trixie: resolved (fixed in 1:1.0.3-2)
debian
CVE-2025-59031P4MEDIUMCVSS 4.3fixed in dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm)2025
CVE-2025-59031 [MEDIUM] CVE-2025-59031: dovecot - Dovecot has provided a script to use for attachment to text conversion. This scr... Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly availab
debian
CVE-2011-4318P4LOWCVSS 5.8fixed in dovecot 1:2.0.18-1 (bookworm)2011
CVE-2011-4318 [MEDIUM] CVE-2011-4318: dovecot - Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is use... Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname. Scope: local bookw
debian
CVE-2006-2414P4LOWCVSS 5.0fixed in dovecot 1.0.beta8-1 (bookworm)2006
CVE-2006-2414 [MEDIUM] CVE-2006-2414: dovecot - Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote atta... Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command. Scope: local bookworm: resolved (fixed in 1.0.beta8-1) bullseye: resolved (fixed in 1.0.beta8-1) forky: resolved (fixed in 1.0.beta8
debian
CVE-2009-3897P4MEDIUMCVSS 5.5fixed in dovecot 1:1.2.8-1 (bookworm)2009
CVE-2009-3897 [MEDIUM] CVE-2009-3897: dovecot - Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain dire... Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself. Scope: local bookworm: resolved (fixed in 1:1.2.8-1) bullseye: r
debian
CVE-2011-1929P4MEDIUMCVSS 5.0fixed in dovecot 1:2.0.13-1 (bookworm)2011
CVE-2011-1929 [MEDIUM] CVE-2011-1929: dovecot - lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before... lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message. Scope: local bookworm: resolved (fixed in 1:2.0.13-1) bullseye: resolved (fixed in 1:2.0.13-1) f
debian
CVE-2010-0745P4LOWCVSS 5.0fixed in dovecot 1:1.2.11-1 (bookworm)2010
CVE-2010-0745 [MEDIUM] CVE-2010-0745: dovecot - Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers... Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message. Scope: local bookworm: resolved (fixed in 1:1.2.11-1) bullseye: resolved (fixed in 1:1.2.11-1) forky: resolved (fixed in 1:1.2.11-1) sid: resolved (fixed in 1:1.2.11-1) trixie: resolved (fixed in 1:1.2
debian
CVE-2020-28200P4MEDIUMCVSS 4.3fixed in dovecot 1:2.3.16+dfsg1-1 (bookworm)2020
CVE-2020-28200 [MEDIUM] CVE-2020-28200: dovecot - The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumpti... The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension. Scope: local bookworm: resolved (fixed in 1:2.3.16+dfsg1-1) bullseye: open forky: resolved (fixed in 1:2.3.16+dfsg1-1) sid: resolved (fixed in 1:2.3.16+dfsg1-1) trixie: resolved (fixed in 1:2.
debian
CVE-2009-2632P4MEDIUMCVSS 4.4fixed in dovecot 1:1.2.1-1 (bookworm)2009
CVE-2009-2632 [MEDIUM] CVE-2009-2632: dovecot - Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus... Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer leng
debian
Debian Dovecot vulnerabilities | cvebase