VendorsAlpine Projectalpineany version
Vulnerabilities

Alpine Project Alpine any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2020-14929
Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
Published 2020-06-19 · Modified
7.5EPSS 0.018
CVE-2022-23553
URL access filters bypass in Alpine
Published 2022-12-28 · Modified
7.5EPSS 0.008
CVE-2022-23554
Authentication bypass in Alpine
Published 2022-12-28 · Modified
6.5EPSS 0.007
CVE-2021-38370
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.
Published 2021-08-10 · Modified
5.9EPSS 0.016
CVE-2021-46853
Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.
Published 2022-11-03 · Modified
5.9EPSS 0.009