VDB
GCVE-110-CERTCC-2020-390745
GCVE-110-CERTCC-2020-390745
Advisory PublishedCVSS 10.0/10
Qualys Research Labs found that the smtp_mailaddr() function in OpenSMTPD version 6.6 does not properly sanitize user input, which could allow a local attacker to escalate their privileges, and allow either a local or remote attacker to execute arbitrary code as root.
Risk Scores
CVSS 2.0
10.0/10
Critical · AV:N/AC:L/Au:N/C:C/I:C/A:C
certcc-cam
certcc-cam
impact0population0exploitation0widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_direct_report0
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score10remediation_levelNDreport_confidenceNDenvironmental_score9.99449472target_distributionNDenvironmental_vectorCDP:ND/TD:ND/CR:ND/IR:ND/AR:ND
Aliases
References
Browse GCVE Records
74,557 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.