Libspf2 is a specialized library implementing the Sender Policy Framework (SPF) protocol for email authentication, with a narrow product scope centered on the single libspf2 codebase. Observed vulnerabilities in this vendor cluster around out-of-bounds write conditions, reflecting the parsing and memory-management demands of protocol-level string handling; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libspf2 over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42118HIGH Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim | May 3, 2024 | 8.8 | 55 | NO | NO |
CVE-2021-33912CRITICAL libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on | Jan 19, 2022 | 9.8 | 37 | NO | NO |
CVE-2021-33913CRITICAL libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Inter | Jan 19, 2022 | 9.8 | 35 | NO | NO |
CVE-2021-20314CRITICAL Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF exp | Aug 12, 2021 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libspf2.
Media articles that mention a CVE ID that affects a product developed by Libspf2 — matched by CVE ID, not by vendor name.