Libesmtp is a focused SMTP client library used for email transmission functionality in applications, with a narrow product portfolio concentrated on the core library itself. The observed vulnerability profile centers on the library's email-protocol handling surface; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libesmtp over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19977CRITICAL libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read. | Dec 26, 2019 | 9.8 | 30 | NO | NO |
CVE-2002-1090HIGH Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial | Oct 4, 2002 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libesmtp.
Media articles that mention a CVE ID that affects a product developed by Libesmtp — matched by CVE ID, not by vendor name.