Where
-Infinity
0

Dovecot dovecotLast updated 2 June 2026

Risk 23
Severity
4.3
First published (updated )

Dovecot dovecotLast updated 2 June 2026

Risk 46
Severity
7.5
First published (updated )

Dovecot Pigeonhole (Sieve)Last updated 2 June 2026

Risk 40
Severity
6.5
First published (updated )

Dovecot dovecotLast updated 2 June 2026

Risk 54
Severity
6.8
First published (updated )

Dovecot dovecotSQL Injection

Risk 70
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Dovecot Dovecot ManageSieveAttacker can send a specifically crafted message before authentication that causes managesieve to al…

Risk 33
Severity
7
First published (updated )

Dovecot doveadmDoveadm credentials are verified using direct comparison which is susceptible to timing oracle attac…

Risk 33
Severity
7
First published (updated )

Open-Xchange DovecotA mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much C…

Risk 28
Severity
5.3
First published (updated )

Dovecot Dovecot (LDAP authentication)If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP au…

Risk 28
Severity
5.3
First published (updated )

Open-Xchange DovecotAttacker can send a specifically crafted message before authentication that causes managesieve to al…

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Open-Xchange DovecotSending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage…

Risk 46
Severity
7.5
First published (updated )

Open-Xchange DovecotDoveadm credentials are verified using direct comparison which is susceptible to timing oracle attac…

Risk 59
Severity
7.4
First published (updated )

Dovecot dovecotSQL Injection

Risk 57
Severity
8.2
First published (updated )

Dovecot dovecotDovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache i…

Risk 53
Severity
6.8
First published (updated )

Dovecot dovecotPath Traversal

Risk 28
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Dovecot Dovecot ManageSieveInput Validation

Risk 46
Severity
7.5
First published (updated )

Open-Xchange DovecotInfoleak

Risk 23
Severity
4.3
First published (updated )

Dovecot dovecotInput Validation

Risk 45
Severity
7.5
First published (updated )

Dovecot IMAP ServerDovecot IMAP Server: Using auth caching causes the first lookup to be cached for all lookups

Risk 60
Severity
7.4
First published (updated )

CVE-2025-30189: Dovecot IMAP Server: Using auth caching causes the first lookup to be cached for all lookups

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Dovecot dovecotDovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be C…

Risk 27
Severity
5.3
First published (updated )

Dovecot dovecotVulnerability Details: Very large headers can cause resource exhaustion when parsing message. The me…

Risk 18
Severity
4
First published (updated )

Dovecot dovecotVulnerability Details: Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes ex…

Risk 18
Severity
4
First published (updated )

Dovecot CVE-2024-23185: Very large headers can cause source exhaustion when parsing message

Dovecot CVE-2024-23184: Having a large number of addss headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Dovecot dovecotAn issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb …

Risk 79
Severity
8.8
First published (updated )

Fedoraproject FedoraThe Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated …

Risk 22
Severity
4.3
First published (updated )

Fedoraproject FedoraCommand Injection

Risk 35
Severity
5.8
First published (updated )

Fedoraproject FedoraPath Traversal

Risk 53
Severity
7.5
First published (updated )

debian/dovecotAn issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can …

Risk 52
Severity
6.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203