Записи Postfix
12 опубликованных записей вендора postfix.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 83,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
33Наблюдать | CVE-2011-1720Эксплойта нет | The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authenticpostfix · postfix · CWE-119 | Средняя6,8 | — | 21,5 % | 13 мая 2011 г. |
32Наблюдать | CVE-2011-0411Эксплойта нет | The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properlpostfix · postfix · CWE-264 | Средняя6,8 | — | 16,3 % | 16 мар. 2011 г. |
31Наблюдать | CVE-2017-10140Эксплойта нет | Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leverapostfix · postfix | Высокая7,8 | — | 0,5 % | 16 апр. 2018 г. |
30Наблюдать | CVE-2026-43964Эксплойта нет | Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced statupostfix · postfix · CWE-193 | Высокая7,5 | — | 0,9 % | 4 мая 2026 г. |
27Наблюдать | CVE-2012-0811Эксплойта нет | Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrarpostfix · postfix · CWE-89 | Средняя6,5 | — | 1,7 % | 1 окт. 2014 г. |
27Наблюдать | CVE-2009-2939Эксплойта нет | The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postpostfix · postfix · CWE-59 | Средняя6,9 | — | 0,5 % | 21 сент. 2009 г. |
27Наблюдать | CVE-2008-4977Эксплойта нет | postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdoupostfix · postfix · CWE-59 | Средняя6,9 | — | 0,4 % | 6 нояб. 2008 г. |
24Наблюдать | CVE-2008-2936Proof of concept | Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to sympostfix · postfix · CWE-264 | Средняя6,2 | — | 1,0 % | 18 авг. 2008 г. |
22Наблюдать | CVE-2023-51764Proof of concept | Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_kpostfix · postfix · CWE-345 | Средняя5,3 | — | 2,6 % | 24 дек. 2023 г. |
21Наблюдать | CVE-2020-12063Эксплойта нет | A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demopostfix · postfix | Средняя5,3 | — | 0,9 % | 24 апр. 2020 г. |
8Наблюдать | CVE-2008-3889Эксплойта нет | Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors dlinux · linux kernel · CWE-20 | Низкая2,1 | — | 0,7 % | 12 сент. 2008 г. |
7Наблюдать | CVE-2008-2937Эксплойта нет | Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allpostfix · postfix · CWE-200 | Низкая1,9 | — | 0,4 % | 18 авг. 2008 г. |
- CVE-2011-172033Наблюдать
The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentic
СредняяCVSS 6,8Эксплойта нетEPSS 21 %postfix · postfix13 мая 2011 г.
- CVE-2011-041132Наблюдать
The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properl
СредняяCVSS 6,8Эксплойта нетEPSS 16 %postfix · postfix16 мар. 2011 г.
- CVE-2017-1014031Наблюдать
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by levera
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %postfix · postfix16 апр. 2018 г.
- CVE-2026-4396430Наблюдать
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced statu
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %postfix · postfix4 мая 2026 г.
- CVE-2012-081127Наблюдать
Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrar
СредняяCVSS 6,5Эксплойта нетEPSS 2 %postfix · postfix1 окт. 2014 г.
- CVE-2009-293927Наблюдать
The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/post
СредняяCVSS 6,9Эксплойта нетEPSS 0 %postfix · postfix21 сент. 2009 г.
- CVE-2008-497727Наблюдать
postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdou
СредняяCVSS 6,9Эксплойта нетEPSS 0 %postfix · postfix6 нояб. 2008 г.
- CVE-2008-293624Наблюдать
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to sym
СредняяCVSS 6,2Proof of conceptEPSS 1 %postfix · postfix18 авг. 2008 г.
- CVE-2023-5176422Наблюдать
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_k
СредняяCVSS 5,3Proof of conceptEPSS 3 %postfix · postfix24 дек. 2023 г.
- CVE-2020-1206321Наблюдать
A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demo
СредняяCVSS 5,3Эксплойта нетEPSS 1 %postfix · postfix24 апр. 2020 г.
- CVE-2008-38898Наблюдать
Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors d
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %linux · linux kernel12 сент. 2008 г.
- CVE-2008-29377Наблюдать
Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which all
НизкаяCVSS 1,9Эксплойта нетEPSS 0 %postfix · postfix18 авг. 2008 г.