Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-19722

21
FAUCET Score

CVE-2019-19722 is a NULL Pointer Dereference vulnerability affecting Dovecot versions prior to 2.3.9.2, including various Fedora distributions. An unauthenticated attacker can crash a push-notification driver by sending a specially crafted email with a group address as either the sender or recipient. This vulnerability has a CVSS score of 5.3 (Medium), indicating low attack complexity and no user interaction required, but only results in a denial of service (availability impact). There is currently no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.3.9.2CPE matchmatch criteria
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
30CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.48%
Probability of exploitation in next 30 days
EPSS Percentile
82.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0248 is in the 74th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

denopatch availablevia llm_extracted
View patch
drupalpatch availablevia llm_extracted
View patch
freeswitchpatch availablevia llm_extracted
View patch
synologypatch availablevia llm_extracted
Fixed in: null
View patch
boschvendor investigatingvia llm_extracted
View patch
broadcomvendor investigatingvia llm_extracted
View patch
ubiquitivendor investigatingvia llm_extracted
View patch

Vendor Advisories (8)

redhatCVE-2019-19722Moderate

dovecot: null pointer dereference in push notification driver

Dec 13, 2019
drupalllm-drupal-276eb547f68c9304CRITICAL

Critical vulnerability in Dovecot

Dec 13, 2019
ubiquitillm-ubiquiti-6a064e24b6a91d38CRITICAL

Critical vulnerability in Dovecot

Dec 13, 2019
synologyllm-synology-9becaf45ca2c5586CRITICAL

Critical vulnerability in Dovecot

Dec 13, 2019
denollm-deno-715dee1695c073cdCRITICAL

Critical vulnerability in Dovecot

Dec 13, 2019
broadcomllm-broadcom-506e2919bce99993CRITICAL

CVE-2019-19722: Critical vulnerability in Dovecot

Dec 13, 2019
freeswitchllm-freeswitch-1505d732917b80e4

Critical vulnerability in Dovecot

Dec 13, 2019
boschllm-bosch-107d78d4cf0c4875CRITICAL

CVE-2019-19722: Critical vulnerability in Dovecot

Dec 13, 2019

References

dovecot.org / list/dovecot-news/2019-December/000428.html
Vendor Advisory
dovecot.org / pipermail/dovecot-news/2019-December/000428.html
Vendor Advisory
dovecot.org / security.html
Vendor Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/4OZCJ3RBA4WIYGN7SOV4TW2AIHXPZATK
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/6PPB7PG5BM3MC5ZF2KHQ3UR7CZIO42BB
openwall.com / lists/oss-security/2019/12/13/3
Mailing ListThird Party Advisory