Known vulnerabilities in OpenSMTPD 6.6.1

Vendor: OpenBSD
Software: OpenSMTPD
Version: 6.6.1
Software CPE: cpe:2.3:a:openbsd:opensmtpd:*:*:*:*:*:*:*:*
Total vulnerabilities: 7
Public exploits: 3
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting OpenSMTPD version 6.6.1 OpenSMTPD 6.6.1 is affected by 7 vulnerabilities: 1 critical, 4 medium, 2 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU77501 - Out-of-bounds read
CWE-125 Medium
No
No
7.3.0p0 19.06.2023 SB2023061904
#VU77500 - Resource Management Errors
CWE-399 Low
No
No
7.3.0p0 19.06.2023 SB2023061904
#VU49179 - NULL Pointer Dereference
CVE-2020-35680
CWE-476 Medium
No
No
6.8.0p1 24.12.2020 SB2020122905
SB2021011259
SB2021052608
and 4 more
#VU49180 - Missing release of memory after effective lifetime
CVE-2020-35679
CWE-401 Medium
No
No
6.8.0p1 24.12.2020 SB2020122905
SB2021011259
SB2021052608
and 4 more
#VU25625 - Out-of-bounds read
CVE-2020-8794
CWE-125 Medium
Public exploit available
No
6.6.4p1 26.02.2020 SB2020022510
SB2020022801
SB2020022901
and 7 more
#VU25586 - Permissions, Privileges, and Access Controls
CVE-2020-8793
CWE-264 Low
Public exploit available
No
6.6.4p1 25.02.2020 SB2020022510
SB2020030314
SB2020022454
and 4 more
#VU24745 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-7247
CWE-78 Critical
Public exploit available
Exploited
6.6.2, 6.6.2p1 29.01.2020 SB2020012920
SB2020012921
SB2020013013
and 4 more