VendorsOpenBSDopensmtpdany version
Vulnerabilities

OpenBSD OpenSMTPD any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2015-7687
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.
Published 2017-10-16 · Modified
9.8EPSS 0.040
CVE-2013-2125
OpenSMTPD before 5.3.2 does not properly handle SSL sessions, which allows remote attackers to cause a denial of service (connection blocking) by keeping a connection open.
Published 2014-05-27 · Modified
5.0EPSS 0.025