Vulnerabilities > Maildrop

DATE CVE VULNERABILITY TITLE RISK
2010-02-04 CVE-2010-0301 Permissions, Privileges, and Access Controls vulnerability in Maildrop
main.C in maildrop 2.3.0 and earlier, when run by root with the -d option, uses the gid of root for execution of the .mailfilter file in a user's home directory, which allows local users to gain privileges via a crafted file.
6.9
2005-08-30 CVE-2005-2655 Unspecified vulnerability in Maildrop
lockmail in maildrop before 1.5.3 does not drop privileges before executing commands, which allows local users to gain privileges via command line arguments.
network
low complexity
maildrop
critical
10.0