Postfix records
12 published records for vendor postfix.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 83.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2011-1720No exploit | The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authenticpostfix · postfix · CWE-119 | Medium6.8 | — | 21.5% | May 13, 2011 |
32Monitor | CVE-2011-0411No exploit | The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properlpostfix · postfix · CWE-264 | Medium6.8 | — | 16.3% | Mar 16, 2011 |
31Monitor | CVE-2017-10140No exploit | Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leverapostfix · postfix | High7.8 | — | 0.5% | Apr 16, 2018 |
30Monitor | CVE-2026-43964No exploit | Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced statupostfix · postfix · CWE-193 | High7.5 | — | 0.9% | May 4, 2026 |
27Monitor | CVE-2012-0811No exploit | Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrarpostfix · postfix · CWE-89 | Medium6.5 | — | 1.7% | Oct 1, 2014 |
27Monitor | CVE-2009-2939No exploit | The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postpostfix · postfix · CWE-59 | Medium6.9 | — | 0.5% | Sep 21, 2009 |
27Monitor | CVE-2008-4977No exploit | postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdoupostfix · postfix · CWE-59 | Medium6.9 | — | 0.4% | Nov 6, 2008 |
24Monitor | CVE-2008-2936Proof of concept | Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to sympostfix · postfix · CWE-264 | Medium6.2 | — | 1.0% | Aug 18, 2008 |
22Monitor | CVE-2023-51764Proof of concept | Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_kpostfix · postfix · CWE-345 | Medium5.3 | — | 2.6% | Dec 24, 2023 |
21Monitor | CVE-2020-12063No exploit | A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demopostfix · postfix | Medium5.3 | — | 0.9% | Apr 24, 2020 |
8Monitor | CVE-2008-3889No exploit | Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors dlinux · linux kernel · CWE-20 | Low2.1 | — | 0.7% | Sep 12, 2008 |
7Monitor | CVE-2008-2937No exploit | Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allpostfix · postfix · CWE-200 | Low1.9 | — | 0.4% | Aug 18, 2008 |
- CVE-2011-172033Monitor
The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentic
MediumCVSS 6.8No exploitEPSS 21%postfix · postfixMay 13, 2011
- CVE-2011-041132Monitor
The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properl
MediumCVSS 6.8No exploitEPSS 16%postfix · postfixMar 16, 2011
- CVE-2017-1014031Monitor
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by levera
HighCVSS 7.8No exploitEPSS 1%postfix · postfixApr 16, 2018
- CVE-2026-4396430Monitor
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced statu
HighCVSS 7.5No exploitEPSS 1%postfix · postfixMay 4, 2026
- CVE-2012-081127Monitor
Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrar
MediumCVSS 6.5No exploitEPSS 2%postfix · postfixOct 1, 2014
- CVE-2009-293927Monitor
The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/post
MediumCVSS 6.9No exploitEPSS 0%postfix · postfixSep 21, 2009
- CVE-2008-497727Monitor
postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdou
MediumCVSS 6.9No exploitEPSS 0%postfix · postfixNov 6, 2008
- CVE-2008-293624Monitor
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to sym
MediumCVSS 6.2Proof of conceptEPSS 1%postfix · postfixAug 18, 2008
- CVE-2023-5176422Monitor
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_k
MediumCVSS 5.3Proof of conceptEPSS 3%postfix · postfixDec 24, 2023
- CVE-2020-1206321Monitor
A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demo
MediumCVSS 5.3No exploitEPSS 1%postfix · postfixApr 24, 2020
- CVE-2008-38898Monitor
Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors d
LowCVSS 2.1No exploitEPSS 1%linux · linux kernelSep 12, 2008
- CVE-2008-29377Monitor
Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which all
LowCVSS 1.9No exploitEPSS 0%postfix · postfixAug 18, 2008