sendmail kayıtları
sendmail üreticisine ait 33 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %60,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-399 Resource Management Errors2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-295 Improper Certificate Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
33 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2002-1337Kavram kanıtı | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Kritik10,0 | — | %72,6 | 7 Mar 2003 |
60Bu hafta | CVE-2003-0694Silahlaştırılmış | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Kritik10,0 | — | %66,2 | 6 Eki 2003 |
52Planlayın | CVE-2003-0161Kavram kanıtı | The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char sendmail · sendmail | Kritik10,0 | — | %38,8 | 2 Nis 2003 |
39İzleyin | CVE-2006-0058Kavram kanıtı | Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in asendmail · sendmail | Yüksek7,6 | — | %28,7 | 22 Mar 2006 |
37İzleyin | CVE-2003-0681Kavram kanıtı | A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) msendmail · advanced message server | Yüksek7,5 | — | %22,4 | 6 Eki 2003 |
32İzleyin | CVE-2007-2246İstismar yok | Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.hp · hp-ux · CWE-399 | Yüksek7,8 | — | %2,3 | 25 Nis 2007 |
31İzleyin | CVE-2006-4434İstismar yok | Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line"sendmail · sendmail · CWE-416 | Yüksek7,5 | — | %4,5 | 28 Ağu 2006 |
31İzleyin | CVE-2002-0906İstismar yok | Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a sendmail · sendmail | Yüksek7,5 | — | %4,4 | 4 Eki 2002 |
31İzleyin | CVE-2009-4565İstismar yok | sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-isendmail · sendmail · CWE-310 | Yüksek7,5 | — | %2,4 | 4 Oca 2010 |
31İzleyin | CVE-2002-2261İstismar yok | Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a bsendmail · sendmail · CWE-264 | Yüksek7,5 | — | %2,0 | 31 Ara 2002 |
30İzleyin | CVE-2021-3618İstismar yok | ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatibf5 · nginx · CWE-295 | Yüksek7,4 | — | %2,0 | 23 Mar 2022 |
30İzleyin | CVE-1999-1592İstismar yok | Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impactsun · sunos | Yüksek7,5 | — | %1,0 | 31 Ara 1999 |
30İzleyin | CVE-2006-7175İstismar yok | The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encrypsendmail · sendmail | Yüksek7,5 | — | %0,8 | 27 Mar 2007 |
28İzleyin | CVE-1999-1580İstismar yok | SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifsendmail · sendmail | Yüksek7,2 | — | %1,1 | 23 Ağu 1995 |
28İzleyin | CVE-1999-1309İstismar yok | Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.sendmail · sendmail | Yüksek7,2 | — | %0,4 | 30 Ağu 1996 |
28İzleyin | CVE-2003-0308İstismar yok | The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additionsendmail · sendmail | Yüksek7,2 | — | %0,4 | 15 May 2003 |
25İzleyin | CVE-2002-2423İstismar yok | Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address frsendmail · sendmail · CWE-20 | Orta6,4 | — | %1,2 | 31 Ara 2002 |
24İzleyin | CVE-2009-1490Kavram kanıtı | Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly executsendmail · sendmail · CWE-119 | Orta5,0 | — | %12,6 | 5 May 2009 |
22İzleyin | CVE-1999-1109Kavram kanıtı | Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from thesendmail · sendmail | Orta5,0 | — | %7,2 | 22 Ara 1999 |
22İzleyin | CVE-2006-1173İstismar yok | Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaussendmail · sendmail · CWE-399 | Orta5,0 | — | %5,3 | 7 Haz 2006 |
21İzleyin | CVE-2003-0688İstismar yok | The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, whsendmail · sendmail | Orta5,0 | — | %3,6 | 20 Eki 2003 |
21İzleyin | CVE-2023-51765İstismar yok | sendmail through 8.17.2 allows SMTP smuggling in certain configurations.sendmail · sendmail · CWE-345 | Orta5,3 | — | %1,1 | 24 Ara 2023 |
20İzleyin | CVE-2005-2070İstismar yok | The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a densendmail · sendmail | Orta5,0 | — | %1,7 | 29 Haz 2005 |
20İzleyin | CVE-1999-0478İstismar yok | Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.sendmail · sendmail | Orta5,0 | — | %1,4 | 1 Ara 1998 |
18İzleyin | CVE-2006-7176İstismar yok | The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name sendmail · sendmail | Orta4,3 | — | %2,0 | 27 Mar 2007 |
- CVE-2002-133762Bu hafta
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
KritikCVSS 10,0Kavram kanıtıEPSS %73sendmail · sendmail7 Mar 2003
- CVE-2003-069460Bu hafta
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
KritikCVSS 10,0SilahlaştırılmışEPSS %66sendmail · advanced message server6 Eki 2003
- CVE-2003-016152Planlayın
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char
KritikCVSS 10,0Kavram kanıtıEPSS %39sendmail · sendmail2 Nis 2003
- CVE-2006-005839İzleyin
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a
YüksekCVSS 7,6Kavram kanıtıEPSS %29sendmail · sendmail22 Mar 2006
- CVE-2003-068137İzleyin
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) m
YüksekCVSS 7,5Kavram kanıtıEPSS %22sendmail · advanced message server6 Eki 2003
- CVE-2007-224632İzleyin
Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.
YüksekCVSS 7,8İstismar yokEPSS %2hp · hp-ux25 Nis 2007
- CVE-2006-443431İzleyin
Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line"
YüksekCVSS 7,5İstismar yokEPSS %5sendmail · sendmail28 Ağu 2006
- CVE-2002-090631İzleyin
Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a
YüksekCVSS 7,5İstismar yokEPSS %4sendmail · sendmail4 Eki 2002
- CVE-2009-456531İzleyin
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-i
YüksekCVSS 7,5İstismar yokEPSS %2sendmail · sendmail4 Oca 2010
- CVE-2002-226131İzleyin
Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a b
YüksekCVSS 7,5İstismar yokEPSS %2sendmail · sendmail31 Ara 2002
- CVE-2021-361830İzleyin
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatib
YüksekCVSS 7,4İstismar yokEPSS %2f5 · nginx23 Mar 2022
- CVE-1999-159230İzleyin
Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact
YüksekCVSS 7,5İstismar yokEPSS %1sun · sunos31 Ara 1999
- CVE-2006-717530İzleyin
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryp
YüksekCVSS 7,5İstismar yokEPSS %1sendmail · sendmail27 Mar 2007
- CVE-1999-158028İzleyin
SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modif
YüksekCVSS 7,2İstismar yokEPSS %1sendmail · sendmail23 Ağu 1995
- CVE-1999-130928İzleyin
Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
YüksekCVSS 7,2İstismar yokEPSS %0sendmail · sendmail30 Ağu 1996
- CVE-2003-030828İzleyin
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain addition
YüksekCVSS 7,2İstismar yokEPSS %0sendmail · sendmail15 May 2003
- CVE-2002-242325İzleyin
Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address fr
OrtaCVSS 6,4İstismar yokEPSS %1sendmail · sendmail31 Ara 2002
- CVE-2009-149024İzleyin
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execut
OrtaCVSS 5,0Kavram kanıtıEPSS %13sendmail · sendmail5 May 2009
- CVE-1999-110922İzleyin
Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the
OrtaCVSS 5,0Kavram kanıtıEPSS %7sendmail · sendmail22 Ara 1999
- CVE-2006-117322İzleyin
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaus
OrtaCVSS 5,0İstismar yokEPSS %5sendmail · sendmail7 Haz 2006
- CVE-2003-068821İzleyin
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, wh
OrtaCVSS 5,0İstismar yokEPSS %4sendmail · sendmail20 Eki 2003
- CVE-2023-5176521İzleyin
sendmail through 8.17.2 allows SMTP smuggling in certain configurations.
OrtaCVSS 5,3İstismar yokEPSS %1sendmail · sendmail24 Ara 2023
- CVE-2005-207020İzleyin
The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a den
OrtaCVSS 5,0İstismar yokEPSS %2sendmail · sendmail29 Haz 2005
- CVE-1999-047820İzleyin
Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.
OrtaCVSS 5,0İstismar yokEPSS %1sendmail · sendmail1 Ara 1998
- CVE-2006-717618İzleyin
The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name
OrtaCVSS 4,3İstismar yokEPSS %2sendmail · sendmail27 Mar 2007