Записи sendmail
33 опубликованных записей вендора sendmail.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 60,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-399 Resource Management Errors2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-295 Improper Certificate Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
33 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2002-1337Proof of concept | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Критическая10,0 | — | 72,6 % | 7 мар. 2003 г. |
60На этой неделе | CVE-2003-0694Готовый эксплойт | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Критическая10,0 | — | 66,2 % | 6 окт. 2003 г. |
52В плане | CVE-2003-0161Proof of concept | The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char sendmail · sendmail | Критическая10,0 | — | 38,8 % | 2 апр. 2003 г. |
39Наблюдать | CVE-2006-0058Proof of concept | Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in asendmail · sendmail | Высокая7,6 | — | 28,7 % | 22 мар. 2006 г. |
37Наблюдать | CVE-2003-0681Proof of concept | A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) msendmail · advanced message server | Высокая7,5 | — | 22,4 % | 6 окт. 2003 г. |
32Наблюдать | CVE-2007-2246Эксплойта нет | Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.hp · hp-ux · CWE-399 | Высокая7,8 | — | 2,3 % | 25 апр. 2007 г. |
31Наблюдать | CVE-2006-4434Эксплойта нет | Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line"sendmail · sendmail · CWE-416 | Высокая7,5 | — | 4,5 % | 28 авг. 2006 г. |
31Наблюдать | CVE-2002-0906Эксплойта нет | Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a sendmail · sendmail | Высокая7,5 | — | 4,4 % | 4 окт. 2002 г. |
31Наблюдать | CVE-2009-4565Эксплойта нет | sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-isendmail · sendmail · CWE-310 | Высокая7,5 | — | 2,4 % | 4 янв. 2010 г. |
31Наблюдать | CVE-2002-2261Эксплойта нет | Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a bsendmail · sendmail · CWE-264 | Высокая7,5 | — | 2,0 % | 31 дек. 2002 г. |
30Наблюдать | CVE-2021-3618Эксплойта нет | ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatibf5 · nginx · CWE-295 | Высокая7,4 | — | 2,0 % | 23 мар. 2022 г. |
30Наблюдать | CVE-1999-1592Эксплойта нет | Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impactsun · sunos | Высокая7,5 | — | 1,0 % | 31 дек. 1999 г. |
30Наблюдать | CVE-2006-7175Эксплойта нет | The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encrypsendmail · sendmail | Высокая7,5 | — | 0,8 % | 27 мар. 2007 г. |
28Наблюдать | CVE-1999-1580Эксплойта нет | SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifsendmail · sendmail | Высокая7,2 | — | 1,1 % | 23 авг. 1995 г. |
28Наблюдать | CVE-1999-1309Эксплойта нет | Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.sendmail · sendmail | Высокая7,2 | — | 0,4 % | 30 авг. 1996 г. |
28Наблюдать | CVE-2003-0308Эксплойта нет | The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additionsendmail · sendmail | Высокая7,2 | — | 0,4 % | 15 мая 2003 г. |
25Наблюдать | CVE-2002-2423Эксплойта нет | Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address frsendmail · sendmail · CWE-20 | Средняя6,4 | — | 1,2 % | 31 дек. 2002 г. |
24Наблюдать | CVE-2009-1490Proof of concept | Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly executsendmail · sendmail · CWE-119 | Средняя5,0 | — | 12,6 % | 5 мая 2009 г. |
22Наблюдать | CVE-1999-1109Proof of concept | Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from thesendmail · sendmail | Средняя5,0 | — | 7,2 % | 22 дек. 1999 г. |
22Наблюдать | CVE-2006-1173Эксплойта нет | Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaussendmail · sendmail · CWE-399 | Средняя5,0 | — | 5,3 % | 7 июн. 2006 г. |
21Наблюдать | CVE-2003-0688Эксплойта нет | The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, whsendmail · sendmail | Средняя5,0 | — | 3,6 % | 20 окт. 2003 г. |
21Наблюдать | CVE-2023-51765Эксплойта нет | sendmail through 8.17.2 allows SMTP smuggling in certain configurations.sendmail · sendmail · CWE-345 | Средняя5,3 | — | 1,1 % | 24 дек. 2023 г. |
20Наблюдать | CVE-2005-2070Эксплойта нет | The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a densendmail · sendmail | Средняя5,0 | — | 1,7 % | 29 июн. 2005 г. |
20Наблюдать | CVE-1999-0478Эксплойта нет | Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.sendmail · sendmail | Средняя5,0 | — | 1,4 % | 1 дек. 1998 г. |
18Наблюдать | CVE-2006-7176Эксплойта нет | The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name sendmail · sendmail | Средняя4,3 | — | 2,0 % | 27 мар. 2007 г. |
- CVE-2002-133762На этой неделе
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
КритическаяCVSS 10,0Proof of conceptEPSS 73 %sendmail · sendmail7 мар. 2003 г.
- CVE-2003-069460На этой неделе
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
КритическаяCVSS 10,0Готовый эксплойтEPSS 66 %sendmail · advanced message server6 окт. 2003 г.
- CVE-2003-016152В плане
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char
КритическаяCVSS 10,0Proof of conceptEPSS 39 %sendmail · sendmail2 апр. 2003 г.
- CVE-2006-005839Наблюдать
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a
ВысокаяCVSS 7,6Proof of conceptEPSS 29 %sendmail · sendmail22 мар. 2006 г.
- CVE-2003-068137Наблюдать
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) m
ВысокаяCVSS 7,5Proof of conceptEPSS 22 %sendmail · advanced message server6 окт. 2003 г.
- CVE-2007-224632Наблюдать
Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %hp · hp-ux25 апр. 2007 г.
- CVE-2006-443431Наблюдать
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line"
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %sendmail · sendmail28 авг. 2006 г.
- CVE-2002-090631Наблюдать
Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %sendmail · sendmail4 окт. 2002 г.
- CVE-2009-456531Наблюдать
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-i
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sendmail · sendmail4 янв. 2010 г.
- CVE-2002-226131Наблюдать
Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a b
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sendmail · sendmail31 дек. 2002 г.
- CVE-2021-361830Наблюдать
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatib
ВысокаяCVSS 7,4Эксплойта нетEPSS 2 %f5 · nginx23 мар. 2022 г.
- CVE-1999-159230Наблюдать
Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sun · sunos31 дек. 1999 г.
- CVE-2006-717530Наблюдать
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryp
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sendmail · sendmail27 мар. 2007 г.
- CVE-1999-158028Наблюдать
SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modif
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %sendmail · sendmail23 авг. 1995 г.
- CVE-1999-130928Наблюдать
Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %sendmail · sendmail30 авг. 1996 г.
- CVE-2003-030828Наблюдать
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain addition
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %sendmail · sendmail15 мая 2003 г.
- CVE-2002-242325Наблюдать
Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address fr
СредняяCVSS 6,4Эксплойта нетEPSS 1 %sendmail · sendmail31 дек. 2002 г.
- CVE-2009-149024Наблюдать
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execut
СредняяCVSS 5,0Proof of conceptEPSS 13 %sendmail · sendmail5 мая 2009 г.
- CVE-1999-110922Наблюдать
Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the
СредняяCVSS 5,0Proof of conceptEPSS 7 %sendmail · sendmail22 дек. 1999 г.
- CVE-2006-117322Наблюдать
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaus
СредняяCVSS 5,0Эксплойта нетEPSS 5 %sendmail · sendmail7 июн. 2006 г.
- CVE-2003-068821Наблюдать
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, wh
СредняяCVSS 5,0Эксплойта нетEPSS 4 %sendmail · sendmail20 окт. 2003 г.
- CVE-2023-5176521Наблюдать
sendmail through 8.17.2 allows SMTP smuggling in certain configurations.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %sendmail · sendmail24 дек. 2023 г.
- CVE-2005-207020Наблюдать
The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a den
СредняяCVSS 5,0Эксплойта нетEPSS 2 %sendmail · sendmail29 июн. 2005 г.
- CVE-1999-047820Наблюдать
Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.
СредняяCVSS 5,0Эксплойта нетEPSS 1 %sendmail · sendmail1 дек. 1998 г.
- CVE-2006-717618Наблюдать
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name
СредняяCVSS 4,3Эксплойта нетEPSS 2 %sendmail · sendmail27 мар. 2007 г.