CVE-2020-35680 |
AVG-1381 |
Low |
Yes |
Denial of service |
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference... |
CVE-2020-35679 |
AVG-1381 |
High |
Yes |
Information disclosure |
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to... |
CVE-2020-8794 |
AVG-1105 |
Critical |
Yes |
Arbitrary command execution |
An out-of-bounds read vulnerability has been found in the client-side code of OpenSMTPD <= 6.6.3p1, leading to arbitrary command execution via a crafted... |
CVE-2020-7247 |
AVG-1090 |
Critical |
Yes |
Arbitrary command execution |
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root... |