Skip to content
Noroxi

Postfix records

12 published records for vendor postfix.

All records

12 records
  • CVE-2011-1720
    33Monitor

    The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentic

    MediumCVSS 6.8No exploitEPSS 21%

    postfix · postfixMay 13, 2011

  • CVE-2011-0411
    32Monitor

    The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properl

    MediumCVSS 6.8No exploitEPSS 16%

    postfix · postfixMar 16, 2011

  • Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by levera

    HighCVSS 7.8No exploitEPSS 1%

    postfix · postfixApr 16, 2018

  • Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced statu

    HighCVSS 7.5No exploitEPSS 1%

    postfix · postfixMay 4, 2026

  • CVE-2012-0811
    27Monitor

    Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrar

    MediumCVSS 6.5No exploitEPSS 2%

    postfix · postfixOct 1, 2014

  • CVE-2009-2939
    27Monitor

    The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/post

    MediumCVSS 6.9No exploitEPSS 0%

    postfix · postfixSep 21, 2009

  • CVE-2008-4977
    27Monitor

    postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdou

    MediumCVSS 6.9No exploitEPSS 0%

    postfix · postfixNov 6, 2008

  • CVE-2008-2936
    24Monitor

    Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to sym

    MediumCVSS 6.2Proof of conceptEPSS 1%

    postfix · postfixAug 18, 2008

  • Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_k

    MediumCVSS 5.3Proof of conceptEPSS 3%

    postfix · postfixDec 24, 2023

  • A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demo

    MediumCVSS 5.3No exploitEPSS 1%

    postfix · postfixApr 24, 2020

  • Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors d

    LowCVSS 2.1No exploitEPSS 1%

    linux · linux kernelSep 12, 2008

  • Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which all

    LowCVSS 1.9No exploitEPSS 0%

    postfix · postfixAug 18, 2008