Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

88 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.70%—DovecotOpen-xchange Dovecot27/3/20267/10/2026
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly…
AnalizadaMedia (4.3)0.28%—DovecotOpen-xchange Dovecot27/3/20267/10/2026
Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use…
AnalizadaAlta (7.5)0.45%—DovecotOpen-xchange Dovecot27/3/20267/10/2026
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy perfomance penalty…
AplazadaAlta (7.4)0.57%—DovecotAI31/10/202517/6/2026
When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb…
AplazadaAlta (7.5)1.3%—DovecotAI10/9/202417/6/2026
Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large…
AplazadaMedia (5)0.84%—DovecotAI10/9/202417/6/2026
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a…
AplazadaMedia (5.3)0.19%—DovecotAI6/9/202417/6/2026
Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will split mail with LF DOT LF into two mails. Upgrade to latest released version. No…
AnalizadaAlta (8.8)2.3%—DovecotDebian Linux17/7/202217/6/2026
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended…
ModificadaMedia (4.8)2.9%—DovecotFedoraproject FedoraDebian Linux28/6/202117/6/2026
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
ModificadaMedia (4.3)2.0%—DovecotFedoraproject Fedora28/6/202117/6/2026
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.
ModificadaMedia (5.5)0.47%—DovecotFedoraproject Fedora28/6/202117/6/2026
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.
ModificadaAlta (7.5)4.7%—DovecotDebian LinuxFedoraproject Fedora4/1/202117/6/2026
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
ModificadaMedia (6.8)2.8%—DovecotDebian LinuxFedoraproject Fedora4/1/202117/6/2026
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
ModificadaAlta (7.5)6.2%—DovecotDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora12/8/202017/6/2026
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
ModificadaAlta (7.5)6.2%—DovecotDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora12/8/202017/6/2026
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
ModificadaAlta (7.5)5.3%—DovecotDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux12/8/202017/6/2026
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
ModificadaMedia (5.3)8.2%—Dovecot18/5/202017/6/2026
In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.
ModificadaMedia (5.3)6.1%—Dovecot18/5/202017/6/2026
In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.
ModificadaAlta (7.5)7.2%—Dovecot18/5/202017/6/2026
In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.
ModificadaMedia (5.3)1.9%—DovecotFedoraproject Fedora12/2/202017/6/2026
The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the recipient cannot read all of their messages.
ModificadaAlta (7.5)51%—DovecotFedoraproject Fedora12/2/202017/6/2026
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.
ModificadaMedia (5.3)2.5%—DovecotFedoraproject Fedora13/12/201917/6/2026
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
ModificadaBaja (3.3)0.40%—DovecotOpensuse LeapOpensuseRedhat Enterprise Linux5/11/201917/6/2026
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
ModificadaCrítica (9.8)62%—DovecotDovecot PigeonholeDebian LinuxFedoraproject Fedora29/8/201917/6/2026
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.
ModificadaAlta (7.5)2.4%—DovecotFedoraproject FedoraOpensuse Leap8/5/201917/6/2026
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.
Orbitaley — Vulnerabilidades