Vulnerabilities
Vulnerable Software
Dovecot:  >> Dovecot  >> 2.2.36.3  Security Vulnerabilities
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
CVSS Score
5.3
EPSS Score
0.012
Published
2019-12-13
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.
CVSS Score
9.8
EPSS Score
0.486
Published
2019-08-29
The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting to authenticate with an invalid UTF-8 sequence as the username.
CVSS Score
7.5
EPSS Score
0.008
Published
2019-04-24


Contact Us

Shodan ® - All rights reserved