Sploitus

CVE-2019-11500

No indexed exploits for CVE-2019-11500 yet

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

Dovecot
< 2.2.36.4, 2.3.7.2
Dovecot Pigeonhole
< 0.5.7.2
Fix
Available
CVSS 3.0
9.8 CRITICAL
EPSS
62.6% (99th percentile)
Weakness
CWE-787
NVD status
Modified
Published
2019-08-29
CVE-2019-11500 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2019-11500 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2019-11500 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.