Show filters
126 Total Results
Displaying 71-80 of 126
Sort by:
Attacker Value
Unknown
CVE-2020-35679
Disclosure Date: December 24, 2020 (last updated February 22, 2025)
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.
0
Attacker Value
Unknown
CVE-2020-35680
Disclosure Date: December 24, 2020 (last updated February 22, 2025)
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine does not properly maintain the I/O channel between the SMTP engine and the filters layer.
0
Attacker Value
Unknown
CVE-2020-8793
Disclosure Date: February 25, 2020 (last updated February 21, 2025)
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.
0
Attacker Value
Unknown
CVE-2019-19977
Disclosure Date: December 26, 2019 (last updated November 27, 2024)
libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.
0
Attacker Value
Unknown
CVE-2017-18603
Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page parameter.
0
Attacker Value
Unknown
CVE-2017-18518
Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.
0
Attacker Value
Unknown
CVE-2019-8337
Disclosure Date: February 13, 2019 (last updated November 27, 2024)
In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.
0
Attacker Value
Unknown
CVE-2017-16659
Disclosure Date: November 08, 2017 (last updated November 26, 2024)
The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access to the assp user account to install a Trojan horse /usr/share/assp/assp.pl script.
0
Attacker Value
Unknown
CVE-2015-7687
Disclosure Date: October 16, 2017 (last updated November 26, 2024)
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.
0
Attacker Value
Unknown
CVE-2017-2171
Disclosure Date: May 22, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2, Custom Search prior to version 1.36, Donate prior to version 2.1.1, Email Queue prior to version 1.1.2, Error Log Viewer prior to version 1.0.6, Facebook Button prior to version 2.54, Featured Posts prior to version 1.0.1, Gallery Categories prior to version 1.0.9, Gallery prior to version 4.5.0, Google +1 prior to version 1.3.4, Google AdSense prior to version 1.44, Google Analytics prior to version 1.7.1, Google Captcha (reCAPTCHA) prior to version 1.28, Google Maps prior to version 1.3.6, Google Shortlink prior to version 1.5.3, Google Sitemap prior to version 3.0.8, Htaccess prior to version 1.7.6, Job Board prior to version 1.1.3, Latest Posts prior to version 0.3, Limit…
0