VYPR

Libspf2

by Libspf2 Project

CVEs (3)

  • CVE-2021-33913CriJan 19, 2022
    risk 0.64cvss 9.8epss 0.10

    libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of SPF_record_expand_data in spf_expand.c. The amount…

  • CVE-2021-33912CriJan 19, 2022
    risk 0.64cvss 9.8epss 0.10

    libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in…

  • CVE-2023-42118HigMay 3, 2024
    risk 0.54cvss 8.8epss 0.52

    Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim libspf2. Authentication is not required to exploit this vulnerability. The specific flaw exists…