procmail records
5 published records for vendor procmail.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2017-16844No exploit | Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of serprocmail · procmail · CWE-119 | Critical9.8 | — | 12.5% | Nov 16, 2017 |
33Monitor | CVE-2014-3618No exploit | Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possiblprocmail · procmail · CWE-119 | High7.5 | — | 8.5% | Sep 8, 2014 |
31Monitor | CVE-1999-0439No exploit | Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configprocmail · procmail | High7.5 | — | 2.5% | Apr 5, 1999 |
24Monitor | CVE-2001-0905No exploit | Race condition in signal handling of procmail 3.20 and earlier, when running setuid, allows local users to cause a denial of service or gainprocmail · procmail | Medium6.2 | — | 0.3% | Oct 18, 2001 |
4Monitor | CVE-1999-0475No exploit | A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail · procmail | Low1.2 | — | 0.3% | Apr 5, 1999 |
- CVE-2017-1684443Plan
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of ser
CriticalCVSS 9.8No exploitEPSS 13%procmail · procmailNov 16, 2017
- CVE-2014-361833Monitor
Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibl
HighCVSS 7.5No exploitEPSS 9%procmail · procmailSep 8, 2014
- CVE-1999-043931Monitor
Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc config
HighCVSS 7.5No exploitEPSS 3%procmail · procmailApr 5, 1999
- CVE-2001-090524Monitor
Race condition in signal handling of procmail 3.20 and earlier, when running setuid, allows local users to cause a denial of service or gain
MediumCVSS 6.2No exploitEPSS 0%procmail · procmailOct 18, 2001
- CVE-1999-04754Monitor
A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running
LowCVSS 1.2No exploitEPSS 0%procmail · procmailApr 5, 1999