Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.70% | — | DovecotOpen-xchange Dovecot | 27/3/2026 | 7/10/2026 | ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly… | |
| Analizada | Media (4.3) | 0.28% | — | DovecotOpen-xchange Dovecot | 27/3/2026 | 7/10/2026 | Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use… | |
| Analizada | Alta (7.5) | 0.45% | — | DovecotOpen-xchange Dovecot | 27/3/2026 | 7/10/2026 | When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty… | |
| Aplazada | Alta (7.4) | 0.57% | — | DovecotAI | 31/10/2025 | 17/6/2026 | When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb… | |
| Aplazada | Alta (7.5) | 1.3% | — | DovecotAI | 10/9/2024 | 17/6/2026 | Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large… | |
| Aplazada | Media (5) | 0.84% | — | DovecotAI | 10/9/2024 | 17/6/2026 | Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a… | |
| Aplazada | Media (5.3) | 0.19% | — | DovecotAI | 6/9/2024 | 17/6/2026 | Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will split mail with LF DOT LF into two mails. Upgrade to latest released version. No… | |
| Analizada | Alta (8.8) | 2.3% | — | DovecotDebian Linux | 17/7/2022 | 17/6/2026 | An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended… | |
| Modificada | Media (4.8) | 2.9% | — | DovecotFedoraproject FedoraDebian Linux | 28/6/2021 | 17/6/2026 | The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address. | |
| Modificada | Media (4.3) | 2.0% | — | DovecotFedoraproject Fedora | 28/6/2021 | 17/6/2026 | The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension. | |
| Modificada | Media (5.5) | 0.47% | — | DovecotFedoraproject Fedora | 28/6/2021 | 17/6/2026 | Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver. | |
| Modificada | Alta (7.5) | 4.7% | — | DovecotDebian LinuxFedoraproject Fedora | 4/1/2021 | 17/6/2026 | Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts. | |
| Modificada | Media (6.8) | 2.8% | — | DovecotDebian LinuxFedoraproject Fedora | 4/1/2021 | 17/6/2026 | An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure). | |
| Modificada | Alta (7.5) | 6.2% | — | DovecotDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora | 12/8/2020 | 17/6/2026 | In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled. | |
| Modificada | Alta (7.5) | 6.2% | — | DovecotDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora | 12/8/2020 | 17/6/2026 | In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read. | |
| Modificada | Alta (7.5) | 5.3% | — | DovecotDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 12/8/2020 | 17/6/2026 | In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts. | |
| Modificada | Media (5.3) | 8.2% | — | Dovecot | 18/5/2020 | 17/6/2026 | In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart. | |
| Modificada | Media (5.3) | 6.1% | — | Dovecot | 18/5/2020 | 17/6/2026 | In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command. | |
| Modificada | Alta (7.5) | 7.2% | — | Dovecot | 18/5/2020 | 17/6/2026 | In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp. | |
| Modificada | Media (5.3) | 1.9% | — | DovecotFedoraproject Fedora | 12/2/2020 | 17/6/2026 | The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the recipient cannot read all of their messages. | |
| Modificada | Alta (7.5) | 51% | — | DovecotFedoraproject Fedora | 12/2/2020 | 17/6/2026 | lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop. | |
| Modificada | Media (5.3) | 2.5% | — | DovecotFedoraproject Fedora | 13/12/2019 | 17/6/2026 | In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient. | |
| Modificada | Baja (3.3) | 0.40% | — | DovecotOpensuse LeapOpensuseRedhat Enterprise Linux | 5/11/2019 | 17/6/2026 | A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files. | |
| Modificada | Crítica (9.8) | 62% | — | DovecotDovecot PigeonholeDebian LinuxFedoraproject Fedora | 29/8/2019 | 17/6/2026 | In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution. | |
| Modificada | Alta (7.5) | 2.4% | — | DovecotFedoraproject FedoraOpensuse Leap | 8/5/2019 | 17/6/2026 | In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command. |