<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Postfix</title>
  <link>https://cvedaily.com/pages/tags/postfix.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/postfix.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Postfix</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-7460 – mailcow-dockerized contains a stored cross-site scripting vulnerability in the a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7460</guid>
    <pubDate>Wed, 20 May 2026 04:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7460</strong></p>
  <p>mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entries from /api/v1/get/mailq/all, copies server-controlled Postfix queue fields into DataTables rows, and renders several of those fields as HTML without adequate output encoding.    This issue affects mailcow-dockerized: 2026-03b.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-43964 – Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43964</guid>
    <pubDate>Mon, 04 May 2026 19:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-43964</strong></p>
  <p>Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-193</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41232 – Froxlor is open source server administration software. Prior to version 2.3.6, i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41232</guid>
    <pubDate>Thu, 23 Apr 2026 05:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41232</strong></p>
  <p>Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when splitting the email address, passing the local part instead of the domain to `validateLocalDomainOwnership()`. This causes the ownership check to always pass for non-existent "domains," allowing any au…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32249 – Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.013...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32249</guid>
    <pubDate>Thu, 12 Mar 2026 20:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32249</strong></p>
  <p>Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]), incorrectly emits the composing bytes of that character as separate NFA states. This corrupts the NFA postfix stack, resulting in NFA_START_COLL having a NULL out1 point…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32024 – Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32024</guid>
    <pubDate>Tue, 16 Apr 2024 15:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32024</strong></p>
  <p>Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.py` `add_pre_postfix` function. This vulnerability is fixed in 23.1.5.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52626 – In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52626</guid>
    <pubDate>Tue, 26 Mar 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52626</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context  Indirection (*) is of lower precedence than postfix increment (++). Logic in napi_poll context would cause an out-of-bound read by first increment the pointer address by byte address space and then dereference the value. Rather, the intended logic wa…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-27305 – aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27305</guid>
    <pubDate>Tue, 12 Mar 2024 21:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-27305</strong></p>
  <p>aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with fake sender addresses, allowing advanced phishing attacks. This issue is also exi…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-51764 – Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51764</guid>
    <pubDate>Sun, 24 Dec 2023 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-51764</strong></p>
  <p>Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs beca…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-32182 – A Improper Link Resolution Before File Access ('Link Following') vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32182</guid>
    <pubDate>Tue, 19 Sep 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-32182</strong></p>
  <p>A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1; SUSE Linux Enterprise High Performance Computing 15 SP5: before 3.7.3-150500.3.5…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34108 – mailcow is a mail server suite based on Dovecot, Postfix and other open source s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34108</guid>
    <pubDate>Wed, 07 Jun 2023 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34108</strong></p>
  <p>mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration. A vulnerability has been discovered in mailcow which allows an attacker to manipulate internal Dovecot variables by using specially crafted passwords during the authentication process. The issue arises from the behavior of the `passwd-verify.lua` s…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-3569 – Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3569</guid>
    <pubDate>Mon, 17 Oct 2022 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-3569</strong></p>
  <p>Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-271</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33913 – libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33913</guid>
    <pubDate>Wed, 19 Jan 2022 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33913</strong></p>
  <p>libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of SPF_record_expand_data in spf_expand.c. The amount of overflowed data depends on the relationship between the length of an entire domain name and the length of its leftmost…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33912 – libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33912</guid>
    <pubDate>Wed, 19 Jan 2022 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33912</strong></p>
  <p>libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPF_record_expand_data in spf_expand.c. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., wi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-35525 – PostSRSd before 1.11 allows a denial of service (subprocess hang) if Postfix sen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35525</guid>
    <pubDate>Mon, 28 Jun 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-35525</strong></p>
  <p>PostSRSd before 1.11 allows a denial of service (subprocess hang) if Postfix sends certain long data fields such as multiple concatenated email addresses. NOTE: the PostSRSd maintainer acknowledges "theoretically, this error should never occur ... I'm not sure if there's a reliable way to trigger this condition by an external attacker, but it is a security bug in PostSRSd nevertheless."</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-12063 – A certain Postfix 2.10.1-7 package could allow an attacker to send an email from...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12063</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12063</guid>
    <pubDate>Fri, 24 Apr 2020 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-12063</strong></p>
  <p>A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \xce\xbf to the 'o' character. This is potentially relevant when the /etc/postfix/sender_login feature is used, because a spoofed outbound message that uses a configured sender address is blocked with a "Sender address rejected:…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12063">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-16791 – In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect respon...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16791</guid>
    <pubDate>Wed, 22 Jan 2020 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-16791</strong></p>
  <p>In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-757</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-10140 – Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-10140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-10140</guid>
    <pubDate>Mon, 16 Apr 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-10140</strong></p>
  <p>Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-10140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-0811 – Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0811</guid>
    <pubDate>Wed, 01 Oct 2014 14:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-0811</strong></p>
  <p>Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-2655 – SQL injection vulnerability in the gen_show_status function in functions.inc.php...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2655</guid>
    <pubDate>Wed, 02 Apr 2014 16:06:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-2655</strong></p>
  <p>SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbitrary SQL commands via a new alias.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-7176 – config/filter.d/postfix.conf in the postfix filter in Fail2ban before 0.8.11 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7176</guid>
    <pubDate>Sat, 01 Feb 2014 15:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-7176</strong></p>
  <p>config/filter.d/postfix.conf in the postfix filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP address via a crafted e-mail address that matches an improperly designed regular expression.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-1720 – The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1720</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1720</guid>
    <pubDate>Fri, 13 May 2011 17:05:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-1720</strong></p>
  <p>The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH comma…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1720">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-0411 – The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0411</guid>
    <pubDate>Wed, 16 Mar 2011 22:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-0411</strong></p>
  <p>The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-0230 – SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0230</guid>
    <pubDate>Fri, 22 Jan 2010 21:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-0230</strong></p>
  <p>SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-2939 – The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 pac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2939</guid>
    <pubDate>Mon, 21 Sep 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-2939</strong></p>
  <p>The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-4977 – postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4977</guid>
    <pubDate>Thu, 06 Nov 2008 15:55:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-4977</strong></p>
  <p>postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files.  NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-3646 – The Postfix configuration file in Mac OS X 10.5.5 causes Postfix to be network-a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3646</guid>
    <pubDate>Fri, 10 Oct 2008 10:30:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-3646</strong></p>
  <p>The Postfix configuration file in Mac OS X 10.5.5 causes Postfix to be network-accessible when mail is sent from a local command-line tool, which allows remote attackers to send mail to local Mac OS X users.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2008-3889 – Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3889</guid>
    <pubDate>Fri, 12 Sep 2008 16:56:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2008-3889</strong></p>
  <p>Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-2936 – Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2936</guid>
    <pubDate>Mon, 18 Aug 2008 19:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-2936</strong></p>
  <p>Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message.  NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2008-2937 – Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2937</guid>
    <pubDate>Mon, 18 Aug 2008 19:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2008-2937</strong></p>
  <p>Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.</p>
  <p><strong>CVSS:</strong> 1.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-3791 – Buffer overflow in the w_read function in sockets.c in Cami Sardinha and Nigel K...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-3791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-3791</guid>
    <pubDate>Sun, 15 Jul 2007 23:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-3791</strong></p>
  <p>Buffer overflow in the w_read function in sockets.c in Cami Sardinha and Nigel Kukard policyd before 1.81 for Postfix allows remote attackers to cause a denial of service and possibly execute arbitrary code via long SMTP commands.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-3791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-0213 – Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-0213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-0213</guid>
    <pubDate>Sat, 14 Jan 2006 01:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-0213</strong></p>
  <p>Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-0213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-0337 – Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-0337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-0337</guid>
    <pubDate>Mon, 02 May 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-0337</strong></p>
  <p>Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-0337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2005-1127 – Format string vulnerability in the log function in Net::Server 0.87 and earlier,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-1127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-1127</guid>
    <pubDate>Mon, 02 May 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2005-1127</strong></p>
  <p>Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-1127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2004-0925 – Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-0925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-0925</guid>
    <pubDate>Thu, 27 Jan 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2004-0925</strong></p>
  <p>Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-0925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2004-1113 – SQL injection vulnerability in SQLgrey Postfix greylisting service before 1.2.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1113</guid>
    <pubDate>Mon, 10 Jan 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2004-1113</strong></p>
  <p>SQL injection vulnerability in SQLgrey Postfix greylisting service before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) sender or (2) recipient e-mail addresses.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-1088 – Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1088</guid>
    <pubDate>Thu, 02 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-1088</strong></p>
  <p>Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2003-0468 – Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2003-0468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2003-0468</guid>
    <pubDate>Wed, 27 Aug 2003 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2003-0468</strong></p>
  <p>Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2003-0468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2003-0540 – The address parser code in Postfix 1.1.12 and earlier allows remote attackers to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2003-0540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2003-0540</guid>
    <pubDate>Wed, 27 Aug 2003 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2003-0540</strong></p>
  <p>The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SM…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2003-0540">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2001-0894 – Vulnerability in Postfix SMTP server before 20010228-pl07, when configured to em...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-0894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-0894</guid>
    <pubDate>Sun, 11 Nov 2001 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2001-0894</strong></p>
  <p>Vulnerability in Postfix SMTP server before 20010228-pl07, when configured to email the postmaster when SMTP errors cause the session to terminate, allows remote attackers to cause a denial of service (memory exhaustion) by generating a large number of SMTP errors, which forces the SMTP session log to grow too large.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-0894">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
