VDB

GCVE-110-CERTCC-2020-390745

GCVE-110-CERTCC-2020-390745
Advisory PublishedCVSS 10.0/10
Vulnetix · Advisory published January 28, 2020
Qualys Research Labs found that the smtp_mailaddr() function in OpenSMTPD version 6.6 does not properly sanitize user input, which could allow a local attacker to escalate their privileges, and allow either a local or remote attacker to execute arbitrary code as root.

Risk Scores

CVSS 2.0
10.0/10
Critical · AV:N/AC:L/Au:N/C:C/I:C/A:C
certcc-cam
certcc-cam
impact0population0exploitation0widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_direct_report0
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score10remediation_levelNDreport_confidenceNDenvironmental_score9.99449472target_distributionNDenvironmental_vectorCDP:ND/TD:ND/CR:ND/IR:ND/AR:ND

Browse GCVE Records

74,557 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›