cbcvebase.

Debian Dovecot vulnerabilities

65 known vulnerabilities affecting debian/dovecot.

Total CVEs
65
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH17MEDIUM29LOW18

Vulnerabilities

Page 4 of 4
CVE-2006-5973P4MEDIUMCVSS 5.0fixed in dovecot 1.0.rc15-1 (bookworm)2006
CVE-2006-5973 [MEDIUM] CVE-2006-5973: dovecot - Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly o... Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file. Scope: local bookworm: resolved (fixed in 1.0.rc15-1) bullseye: resolved (fixed
debian
CVE-2010-3780P4MEDIUMCVSS 4.0fixed in dovecot 1:1.2.15-1 (bookworm)2010
CVE-2010-3780 [MEDIUM] CVE-2010-3780: dovecot - Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial ... Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions. Scope: local bookworm: resolved (fixed in 1:1.2.15-1) bullseye: resolved (fixed in 1:1.2.15-1) forky: resolved (fixed in 1:1.2.15-1) sid: resolved (fixed in 1:1.2.15-1) trixie: resolved
debian
CVE-2006-0730P4MEDIUMCVSS 5.0fixed in dovecot 1.0.beta3-1 (bookworm)2006
CVE-2006-0730 [MEDIUM] CVE-2006-0730: dovecot - Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote att... Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability. Scope: local
debian
CVE-2010-3779P4LOWCVSS 3.5fixed in dovecot 1:1.2.15-1 (bookworm)2010
CVE-2010-3779 [LOW] CVE-2010-3779: dovecot - Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permissi... Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox. Scope: local bookworm: resolved (fixed in 1:1.2.15-1) bullseye: res
debian
CVE-2008-1199P4MEDIUMCVSS 4.4fixed in dovecot 1:1.0.12-1 (bookworm)2008
CVE-2008-1199 [MEDIUM] CVE-2008-1199: dovecot - Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot... Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack. Scope: local bookworm: resolved (fixed in 1:1.0.12-1) bullseye: resolved (fixed in 1:1.0.12-1) forky: r
debian
Debian Dovecot vulnerabilities | cvebase