Libesmtp is a lightweight C library for SMTP client functionality, embedded in mail applications and server components where it handles protocol parsing and message transmission. The durable signal centers on memory-access safety in the library's protocol handling, with observed weaknesses including out-of-bounds reads. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libesmtp Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19977CRITICAL libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read. | Dec 26, 2019 | 9.8 | 30 | NO | NO |
CVE-2002-1090HIGH Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial | Oct 4, 2002 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libesmtp Project.
Media articles that mention a CVE ID that affects a product developed by Libesmtp Project — matched by CVE ID, not by vendor name.