Postfix kayıtları
postfix üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %83,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
33İzleyin | CVE-2011-1720İstismar yok | The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authenticpostfix · postfix · CWE-119 | Orta6,8 | — | %21,5 | 13 May 2011 |
32İzleyin | CVE-2011-0411İstismar yok | The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properlpostfix · postfix · CWE-264 | Orta6,8 | — | %16,3 | 16 Mar 2011 |
31İzleyin | CVE-2017-10140İstismar yok | Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leverapostfix · postfix | Yüksek7,8 | — | %0,5 | 16 Nis 2018 |
30İzleyin | CVE-2026-43964İstismar yok | Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced statupostfix · postfix · CWE-193 | Yüksek7,5 | — | %0,9 | 4 May 2026 |
27İzleyin | CVE-2012-0811İstismar yok | Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrarpostfix · postfix · CWE-89 | Orta6,5 | — | %1,7 | 1 Eki 2014 |
27İzleyin | CVE-2009-2939İstismar yok | The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postpostfix · postfix · CWE-59 | Orta6,9 | — | %0,5 | 21 Eyl 2009 |
27İzleyin | CVE-2008-4977İstismar yok | postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdoupostfix · postfix · CWE-59 | Orta6,9 | — | %0,4 | 6 Kas 2008 |
24İzleyin | CVE-2008-2936Kavram kanıtı | Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to sympostfix · postfix · CWE-264 | Orta6,2 | — | %1,0 | 18 Ağu 2008 |
22İzleyin | CVE-2023-51764Kavram kanıtı | Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_kpostfix · postfix · CWE-345 | Orta5,3 | — | %2,6 | 24 Ara 2023 |
21İzleyin | CVE-2020-12063İstismar yok | A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demopostfix · postfix | Orta5,3 | — | %0,9 | 24 Nis 2020 |
8İzleyin | CVE-2008-3889İstismar yok | Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors dlinux · linux kernel · CWE-20 | Düşük2,1 | — | %0,7 | 12 Eyl 2008 |
7İzleyin | CVE-2008-2937İstismar yok | Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allpostfix · postfix · CWE-200 | Düşük1,9 | — | %0,4 | 18 Ağu 2008 |
- CVE-2011-172033İzleyin
The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentic
OrtaCVSS 6,8İstismar yokEPSS %21postfix · postfix13 May 2011
- CVE-2011-041132İzleyin
The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properl
OrtaCVSS 6,8İstismar yokEPSS %16postfix · postfix16 Mar 2011
- CVE-2017-1014031İzleyin
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by levera
YüksekCVSS 7,8İstismar yokEPSS %1postfix · postfix16 Nis 2018
- CVE-2026-4396430İzleyin
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced statu
YüksekCVSS 7,5İstismar yokEPSS %1postfix · postfix4 May 2026
- CVE-2012-081127İzleyin
Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrar
OrtaCVSS 6,5İstismar yokEPSS %2postfix · postfix1 Eki 2014
- CVE-2009-293927İzleyin
The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/post
OrtaCVSS 6,9İstismar yokEPSS %0postfix · postfix21 Eyl 2009
- CVE-2008-497727İzleyin
postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdou
OrtaCVSS 6,9İstismar yokEPSS %0postfix · postfix6 Kas 2008
- CVE-2008-293624İzleyin
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to sym
OrtaCVSS 6,2Kavram kanıtıEPSS %1postfix · postfix18 Ağu 2008
- CVE-2023-5176422İzleyin
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_k
OrtaCVSS 5,3Kavram kanıtıEPSS %3postfix · postfix24 Ara 2023
- CVE-2020-1206321İzleyin
A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demo
OrtaCVSS 5,3İstismar yokEPSS %1postfix · postfix24 Nis 2020
- CVE-2008-38898İzleyin
Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors d
DüşükCVSS 2,1İstismar yokEPSS %1linux · linux kernel12 Eyl 2008
- CVE-2008-29377İzleyin
Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which all
DüşükCVSS 1,9İstismar yokEPSS %0postfix · postfix18 Ağu 2008