Skip to content
Noroxi

opensmtpd records

6 published records for vendor opensmtpd.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 16.7%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

6 records
  • CVE-2020-8794
    66This week

    OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies.

    CriticalCVSS 9.8WeaponizedEPSS 89%

    opensmtpd · opensmtpdFeb 25, 2020

  • smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointe

    HighCVSS 7.5No exploitEPSS 4%

    opensmtpd · opensmtpdDec 24, 2020

  • smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak v

    HighCVSS 7.5No exploitEPSS 3%

    opensmtpd · opensmtpdDec 24, 2020

  • ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit

    HighCVSS 7.8No exploitEPSS 0%

    opensmtpd · opensmtpdApr 4, 2023

  • Local DoS in OpenSMTPD via UNIX domain socket smtpd.sock

    MediumCVSS 6.9No exploitEPSS 0%

    opensmtpd · opensmtpdNov 20, 2025

  • CVE-2020-8793
    18Monitor

    OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrust

    MediumCVSS 4.7Proof of conceptEPSS 1%

    opensmtpd · opensmtpdFeb 25, 2020