Vulnerabilities > Alpine Project > Alpine > 2.23.1

DATE CVE VULNERABILITY TITLE RISK
2022-11-03 CVE-2021-46853 Unspecified vulnerability in Alpine Project Alpine
Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.
network
high complexity
alpine-project
5.9
2021-08-10 CVE-2021-38370 Command Injection vulnerability in Alpine Project Alpine
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.
network
high complexity
alpine-project CWE-77
5.9