sendmail records
33 published records for vendor sendmail.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3%
- Pre-auth RCE
- 6
- With a fix record
- 60.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-399 Resource Management Errors2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-295 Improper Certificate Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
33 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2002-1337Proof of concept | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Critical10.0 | — | 72.6% | Mar 7, 2003 |
60This week | CVE-2003-0694Weaponized | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Critical10.0 | — | 66.2% | Oct 6, 2003 |
52Plan | CVE-2003-0161Proof of concept | The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char sendmail · sendmail | Critical10.0 | — | 38.8% | Apr 2, 2003 |
39Monitor | CVE-2006-0058Proof of concept | Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in asendmail · sendmail | High7.6 | — | 28.7% | Mar 22, 2006 |
37Monitor | CVE-2003-0681Proof of concept | A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) msendmail · advanced message server | High7.5 | — | 22.4% | Oct 6, 2003 |
32Monitor | CVE-2007-2246No exploit | Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.hp · hp-ux · CWE-399 | High7.8 | — | 2.3% | Apr 25, 2007 |
31Monitor | CVE-2006-4434No exploit | Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line"sendmail · sendmail · CWE-416 | High7.5 | — | 4.5% | Aug 28, 2006 |
31Monitor | CVE-2002-0906No exploit | Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a sendmail · sendmail | High7.5 | — | 4.4% | Oct 4, 2002 |
31Monitor | CVE-2009-4565No exploit | sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-isendmail · sendmail · CWE-310 | High7.5 | — | 2.4% | Jan 4, 2010 |
31Monitor | CVE-2002-2261No exploit | Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a bsendmail · sendmail · CWE-264 | High7.5 | — | 2.0% | Dec 31, 2002 |
30Monitor | CVE-2021-3618No exploit | ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatibf5 · nginx · CWE-295 | High7.4 | — | 2.0% | Mar 23, 2022 |
30Monitor | CVE-1999-1592No exploit | Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impactsun · sunos | High7.5 | — | 1.0% | Dec 31, 1999 |
30Monitor | CVE-2006-7175No exploit | The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encrypsendmail · sendmail | High7.5 | — | 0.8% | Mar 27, 2007 |
28Monitor | CVE-1999-1580No exploit | SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifsendmail · sendmail | High7.2 | — | 1.1% | Aug 23, 1995 |
28Monitor | CVE-1999-1309No exploit | Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.sendmail · sendmail | High7.2 | — | 0.4% | Aug 30, 1996 |
28Monitor | CVE-2003-0308No exploit | The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additionsendmail · sendmail | High7.2 | — | 0.4% | May 15, 2003 |
25Monitor | CVE-2002-2423No exploit | Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address frsendmail · sendmail · CWE-20 | Medium6.4 | — | 1.2% | Dec 31, 2002 |
24Monitor | CVE-2009-1490Proof of concept | Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly executsendmail · sendmail · CWE-119 | Medium5.0 | — | 12.6% | May 5, 2009 |
22Monitor | CVE-1999-1109Proof of concept | Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from thesendmail · sendmail | Medium5.0 | — | 7.2% | Dec 22, 1999 |
22Monitor | CVE-2006-1173No exploit | Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaussendmail · sendmail · CWE-399 | Medium5.0 | — | 5.3% | Jun 7, 2006 |
21Monitor | CVE-2003-0688No exploit | The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, whsendmail · sendmail | Medium5.0 | — | 3.6% | Oct 20, 2003 |
21Monitor | CVE-2023-51765No exploit | sendmail through 8.17.2 allows SMTP smuggling in certain configurations.sendmail · sendmail · CWE-345 | Medium5.3 | — | 1.1% | Dec 24, 2023 |
20Monitor | CVE-2005-2070No exploit | The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a densendmail · sendmail | Medium5.0 | — | 1.7% | Jun 29, 2005 |
20Monitor | CVE-1999-0478No exploit | Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.sendmail · sendmail | Medium5.0 | — | 1.4% | Dec 1, 1998 |
18Monitor | CVE-2006-7176No exploit | The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name sendmail · sendmail | Medium4.3 | — | 2.0% | Mar 27, 2007 |
- CVE-2002-133762This week
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
CriticalCVSS 10.0Proof of conceptEPSS 73%sendmail · sendmailMar 7, 2003
- CVE-2003-069460This week
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
CriticalCVSS 10.0WeaponizedEPSS 66%sendmail · advanced message serverOct 6, 2003
- CVE-2003-016152Plan
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char
CriticalCVSS 10.0Proof of conceptEPSS 39%sendmail · sendmailApr 2, 2003
- CVE-2006-005839Monitor
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a
HighCVSS 7.6Proof of conceptEPSS 29%sendmail · sendmailMar 22, 2006
- CVE-2003-068137Monitor
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) m
HighCVSS 7.5Proof of conceptEPSS 22%sendmail · advanced message serverOct 6, 2003
- CVE-2007-224632Monitor
Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.
HighCVSS 7.8No exploitEPSS 2%hp · hp-uxApr 25, 2007
- CVE-2006-443431Monitor
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line"
HighCVSS 7.5No exploitEPSS 5%sendmail · sendmailAug 28, 2006
- CVE-2002-090631Monitor
Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a
HighCVSS 7.5No exploitEPSS 4%sendmail · sendmailOct 4, 2002
- CVE-2009-456531Monitor
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-i
HighCVSS 7.5No exploitEPSS 2%sendmail · sendmailJan 4, 2010
- CVE-2002-226131Monitor
Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a b
HighCVSS 7.5No exploitEPSS 2%sendmail · sendmailDec 31, 2002
- CVE-2021-361830Monitor
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatib
HighCVSS 7.4No exploitEPSS 2%f5 · nginxMar 23, 2022
- CVE-1999-159230Monitor
Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact
HighCVSS 7.5No exploitEPSS 1%sun · sunosDec 31, 1999
- CVE-2006-717530Monitor
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryp
HighCVSS 7.5No exploitEPSS 1%sendmail · sendmailMar 27, 2007
- CVE-1999-158028Monitor
SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modif
HighCVSS 7.2No exploitEPSS 1%sendmail · sendmailAug 23, 1995
- CVE-1999-130928Monitor
Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
HighCVSS 7.2No exploitEPSS 0%sendmail · sendmailAug 30, 1996
- CVE-2003-030828Monitor
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain addition
HighCVSS 7.2No exploitEPSS 0%sendmail · sendmailMay 15, 2003
- CVE-2002-242325Monitor
Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address fr
MediumCVSS 6.4No exploitEPSS 1%sendmail · sendmailDec 31, 2002
- CVE-2009-149024Monitor
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execut
MediumCVSS 5.0Proof of conceptEPSS 13%sendmail · sendmailMay 5, 2009
- CVE-1999-110922Monitor
Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the
MediumCVSS 5.0Proof of conceptEPSS 7%sendmail · sendmailDec 22, 1999
- CVE-2006-117322Monitor
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaus
MediumCVSS 5.0No exploitEPSS 5%sendmail · sendmailJun 7, 2006
- CVE-2003-068821Monitor
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, wh
MediumCVSS 5.0No exploitEPSS 4%sendmail · sendmailOct 20, 2003
- CVE-2023-5176521Monitor
sendmail through 8.17.2 allows SMTP smuggling in certain configurations.
MediumCVSS 5.3No exploitEPSS 1%sendmail · sendmailDec 24, 2023
- CVE-2005-207020Monitor
The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a den
MediumCVSS 5.0No exploitEPSS 2%sendmail · sendmailJun 29, 2005
- CVE-1999-047820Monitor
Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.
MediumCVSS 5.0No exploitEPSS 1%sendmail · sendmailDec 1, 1998
- CVE-2006-717618Monitor
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name
MediumCVSS 4.3No exploitEPSS 2%sendmail · sendmailMar 27, 2007