SMTP Pentest Guide

SMTP-Related CVEs

A comprehensive list of Common Vulnerabilities and Exposures (CVEs) related to SMTP servers and clients.

CVE IDDescriptionSeverityCVSS ScorePublishedActions
CVE-2023-34011Exim before 4.96.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted SMTP session.Critical9.82023-06-15Details
CVE-2022-30333RARLAB UnRAR in Postfix SMTP server before 6.12 contains a path traversal vulnerability that can be leveraged for remote code execution.Critical9.12022-05-30Details
CVE-2021-41991Sendmail before 8.17.1 allows SMTP command injection via a crafted envelope-from address.High8.62021-10-12Details
CVE-2020-28017Postfix before 3.5.8 allows SMTP command injection via a crafted SMTP session that triggers a buffer overflow.High7.52020-11-03Details
CVE-2019-10149Exim before 4.92 allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.Critical9.82019-06-05Details
CVE-2018-10583Microsoft Exchange Server allows remote attackers to bypass the SMTP authentication via a specific sequence of SMTP commands.Medium6.52018-04-22Details
CVE-2017-5461Mozilla Thunderbird before 52.0 allows remote attackers to execute arbitrary code via crafted SMTP responses that trigger memory corruption.Critical9.32017-03-10Details
CVE-2016-9963Postfix before 3.1.4 allows SMTP command injection via a crafted SMTP session that triggers a buffer overflow in the smtpd process.High8.02016-12-15Details