Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sendmail HIGH 7.5
CVE-2009-4565

sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-mid…

Fix: after 8.14.3
Fix from $1,950 2010-01-04
Sendmail MEDIUM 5.0
CVE-2009-1490EPSS 13%

Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitra…

Fix: after 8.13.1.2
Fix from $1,600 2009-05-05
Sendmail HIGH 7.8
CVE-2007-2246

Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows…

Patch available
Fix from $1,950 2007-04-25
Sendmail HIGH 7.5
CVE-2006-7175

The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, whi…

Mitigation only
Fix from $1,950 2007-03-27
Sendmail HIGH 7.5
CVE-2006-4434

Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which c…

Fix: 8.13.8+
Fix from $1,950 2006-08-29
Sendmail MEDIUM 5.0
CVE-2006-1173EPSS 5%

Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the sta…

Fix: after 8.13.6
Fix from $1,600 2006-06-07
Sendmail HIGH 7.6
CVE-2006-0058EPSS 28%

Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that…

Patch available
Fix from $1,950 2006-03-22
Sendmail MEDIUM 5.0
CVE-2005-2070

The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,600 2005-06-29
Sendmail HIGH 10.0
CVE-2003-0161EPSS 38%

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int t…

Patch available
Fix from $1,950 2003-04-02
Sendmail HIGH 7.5
CVE-2002-2261

Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS …

Patch available
Fix from $1,950 2002-12-31
Sendmail MEDIUM 6.4
CVE-2002-2423

Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being …

Mitigation only
Fix from $1,600 2002-12-31
Sendmail HIGH 7.5
CVE-2002-0906

Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of…

Patch available
Fix from $1,950 2002-10-04
Sendmail HIGH 7.5
CVE-1999-1592

Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact. NOTE: …

Patch available
Fix from $1,950 1999-12-31
Sendmail MEDIUM 5.0
CVE-1999-1109EPSS 7%

Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, …

Fix: after 8.10.0
Fix from $1,600 1999-12-22
Sendmail MEDIUM 5.0
CVE-1999-0478

Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.

Fix: after 8.9.2
Fix from $1,600 1998-12-01
Sendmail HIGH 7.2
CVE-1999-1309

Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.

Fix: after 8.6.7
Fix from $1,950 1996-08-30
Sendmail HIGH 7.2
CVE-1999-1580

SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the …

Patch available
Fix from $1,950 1995-08-23