Vulnerabilities > Dovecot > Dovecot > 2.3.10.1

DATE CVE VULNERABILITY TITLE RISK
2022-07-17 CVE-2022-30550 Improper Authentication vulnerability in multiple products
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20.
network
low complexity
dovecot debian CWE-287
8.8
2021-06-28 CVE-2020-28200 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.
network
low complexity
dovecot fedoraproject CWE-770
4.3
2021-06-28 CVE-2021-33515 Command Injection vulnerability in multiple products
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp.
network
high complexity
dovecot fedoraproject debian CWE-77
4.8
2021-01-04 CVE-2020-25275 Improper Input Validation vulnerability in multiple products
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
network
low complexity
dovecot debian fedoraproject CWE-20
7.5
2021-01-04 CVE-2020-24386 An issue was discovered in Dovecot before 2.3.13.
network
high complexity
dovecot debian fedoraproject
6.8
2020-08-12 CVE-2020-12674 Out-of-bounds Read vulnerability in multiple products
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
network
low complexity
dovecot debian canonical fedoraproject CWE-125
7.5
2020-08-12 CVE-2020-12673 Out-of-bounds Read vulnerability in multiple products
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
network
low complexity
dovecot debian canonical fedoraproject CWE-125
7.5
2020-08-12 CVE-2020-12100 Uncontrolled Recursion vulnerability in multiple products
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
network
low complexity
dovecot debian fedoraproject canonical CWE-674
7.5