opensmtpd records
6 published records for vendor opensmtpd.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 16.7%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read1
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-476 NULL Pointer Dereference1
- CWE-754 Improper Check for Unusual or Exceptional Conditions1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
66This week | CVE-2020-8794Weaponized | OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies.opensmtpd · opensmtpd · CWE-125 | Critical9.8 | — | 88.9% | Feb 25, 2020 |
31Monitor | CVE-2020-35680No exploit | smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointeopensmtpd · opensmtpd · CWE-476 | High7.5 | — | 3.7% | Dec 24, 2020 |
31Monitor | CVE-2020-35679No exploit | smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak vopensmtpd · opensmtpd · CWE-401 | High7.5 | — | 2.9% | Dec 24, 2020 |
31Monitor | CVE-2023-29323No exploit | ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commitopensmtpd · opensmtpd | High7.8 | — | 0.3% | Apr 4, 2023 |
27Monitor | CVE-2025-62875No exploit | Local DoS in OpenSMTPD via UNIX domain socket smtpd.sockopensmtpd · opensmtpd · CWE-754 | Medium6.9 | — | 0.2% | Nov 20, 2025 |
18Monitor | CVE-2020-8793Proof of concept | OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrustopensmtpd · opensmtpd · CWE-367 | Medium4.7 | — | 0.9% | Feb 25, 2020 |
- CVE-2020-879466This week
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies.
CriticalCVSS 9.8WeaponizedEPSS 89%opensmtpd · opensmtpdFeb 25, 2020
- CVE-2020-3568031Monitor
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointe
HighCVSS 7.5No exploitEPSS 4%opensmtpd · opensmtpdDec 24, 2020
- CVE-2020-3567931Monitor
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak v
HighCVSS 7.5No exploitEPSS 3%opensmtpd · opensmtpdDec 24, 2020
- CVE-2023-2932331Monitor
ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit
HighCVSS 7.8No exploitEPSS 0%opensmtpd · opensmtpdApr 4, 2023
- CVE-2025-6287527Monitor
Local DoS in OpenSMTPD via UNIX domain socket smtpd.sock
MediumCVSS 6.9No exploitEPSS 0%opensmtpd · opensmtpdNov 20, 2025
- CVE-2020-879318Monitor
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrust
MediumCVSS 4.7Proof of conceptEPSS 1%opensmtpd · opensmtpdFeb 25, 2020