Show filters
59 Total Results
Displaying 11-20 of 59
Sort by:
Attacker Value
Unknown

CVE-2020-12673

Disclosure Date: August 12, 2020 (last updated February 21, 2025)
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
Attacker Value
Unknown

CVE-2020-12100

Disclosure Date: August 12, 2020 (last updated February 21, 2025)
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
Attacker Value
Unknown

CVE-2020-10967

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.
Attacker Value
Unknown

CVE-2020-10957

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.
Attacker Value
Unknown

CVE-2020-10958

Disclosure Date: May 18, 2020 (last updated February 21, 2025)
In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.
Attacker Value
Unknown

CVE-2020-7046

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.
Attacker Value
Unknown

CVE-2020-7957

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the recipient cannot read all of their messages.
Attacker Value
Unknown

CVE-2019-19722

Disclosure Date: December 13, 2019 (last updated November 08, 2023)
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
Attacker Value
Unknown

CVE-2016-4983

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
Attacker Value
Unknown

CVE-2019-11500

Disclosure Date: August 29, 2019 (last updated November 08, 2023)
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.
0