Known vulnerabilities in dovecot (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:dovecot_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 18
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting dovecot (Debian package) dovecot (Debian package) is affected by 18 known vulnerabilities: 1 high, 13 medium, 4 low Critical High Medium Low

Vulnerabilities (18)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU131865 - Improper Handling of Extra Parameters
CVE-2026-27851
CWE-235 Medium
No
No
1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6 19.05.2026 SB2026051937
SB2026051938
SB2026051939
and 2 more
#VU131866 - Resource exhaustion
CVE-2026-40016
CWE-400 Low
No
No
1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6 19.05.2026 SB2026051937
SB2026053112
SB2026060308
and 1 more
#VU131867 - Improper Control of Resource Identifiers ('Resource Injection')
CVE-2026-33603
CWE-99 Medium
No
No
1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6 19.05.2026 SB2026051937
SB2026051938
SB2026051939
and 4 more
#VU131868 - Improper Access Control
CVE-2026-40020
CWE-284 Low
No
No
1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6 19.05.2026 SB2026051937
SB2026051938
SB2026051939
and 4 more
#VU131869 - Resource exhaustion
CVE-2026-42006
CWE-400 Low
No
No
1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6 19.05.2026 SB2026051937
SB2026051938
SB2026051939
and 14 more
#VU96022 - Resource exhaustion
CVE-2024-23184
CWE-400 Medium
No
No
1:2.3.19.1+dfsg1-2.1+deb12u1 14.08.2024 SB2024081482
SB2024081536
SB2024082002
and 11 more
#VU96021 - Resource exhaustion
CVE-2024-23185
CWE-400 Medium
No
No
1:2.3.19.1+dfsg1-2.1+deb12u1 14.08.2024 SB2024081482
SB2024081536
SB2024082002
and 11 more
#VU49238 - Improper input validation
CVE-2020-25275
CWE-20 Medium
No
No
2.3.4.1-5+deb10u5 04.01.2021 SB2021010411
SB2021010412
SB2021010418
and 9 more
#VU49237 - Exposure of sensitive information to an unauthorized actor
CVE-2020-24386
CWE-200 Medium
No
No
2.3.4.1-5+deb10u5 04.01.2021 SB2021010411
SB2021010412
SB2021010418
and 11 more
#VU45673 - Improper input validation
CVE-2020-12674
CWE-20 Medium
No
No
2.3.4.1-5+deb10u3 13.08.2020 SB2020081309
SB2020081310
SB2020082104
and 15 more
#VU45672 - Out-of-bounds read
CVE-2020-12673
CWE-125 Medium
No
No
2.3.4.1-5+deb10u3 13.08.2020 SB2020081309
SB2020081310
SB2020082104
and 15 more
#VU45671 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-12100
CWE-835 Medium
No
No
2.3.4.1-5+deb10u3, 2.3.4.1-5+deb10u5 13.08.2020 SB2020081309
SB2020081310
SB2020081917
and 16 more
#VU27984 - Improper input validation
CVE-2020-10967
CWE-20 Medium
No
No
1:2.3.4.1-5+deb10u2 18.05.2020 SB2020051816
SB2020051820
SB2020051917
and 11 more
#VU27983 - Use After Free
CVE-2020-10958
CWE-416 Medium
No
No
1:2.3.4.1-5+deb10u2 18.05.2020 SB2020051816
SB2020051820
SB2020051917
and 8 more
#VU27981 - NULL Pointer Dereference
CVE-2020-10957
CWE-476 Medium
No
No
1:2.3.4.1-5+deb10u2 18.05.2020 SB2020051816
SB2020051820
SB2020051917
and 8 more
#VU20432 - Out-of-bounds write
CVE-2019-11500
CWE-787 High
No
No
1:2.2.27-3+deb9u5 28.08.2019 SB2019082801
SB2019082802
SB2019082803
and 15 more
#VU18089 - Stack-based buffer overflow
CVE-2019-7524
CWE-121 Low
No
No
1:2.2.27-3+deb9u4 28.03.2019 SB2019032801
SB2019032901
SB2019040102
and 10 more
#VU17374 - Authentication Bypass Issues
CVE-2019-3814
CWE-592 Medium
No
No
1:2.2.27-3+deb9u3 05.02.2019 SB2019020504
SB2019020615
SB2019020616
and 9 more