VendorsEric Allmansendmailall versions
Vulnerabilities

Eric Allman Sendmail

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-1999-0095
The debug command in Sendmail is enabled, allowing attackers to execute commands as root.
Published 1999-09-29 · Modified
10.01 PoCEPSS 0.163
CVE-1999-0204
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
Published 1999-09-29 · Modified
10.01 PoCEPSS 0.088
CVE-1999-0047
MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.
Published 1999-09-29 · Modified
10.0EPSS 0.031
CVE-1999-0203
In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.
Published 2000-04-25 · Modified
10.0EPSS 0.021
CVE-1999-0206
MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.
Published 1999-09-29 · Modified
10.0EPSS 0.019
CVE-1999-0130
Local users can start Sendmail in daemon mode and gain root privileges.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.011
CVE-1999-0145
Sendmail WIZ command enabled, allowing root access.
Published 2000-10-13 · Modified
7.2EPSS 0.010
CVE-1999-0131
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
Published 1999-09-29 · Modified
7.2EPSS 0.006
CVE-1999-0163
In older versions of Sendmail, an attacker could use a pipe character to execute root commands.
Published 2000-02-04 · Modified
7.2EPSS 0.004
CVE-1999-0393
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
Published 2000-10-13 · Modified
5.01 PoCEPSS 0.024
CVE-2000-0319
mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.
Published 2000-10-13 · Modified
5.0EPSS 0.018
CVE-1999-0205
Denial of service in Sendmail 8.6.11 and 8.6.12.
Published 2000-02-04 · Modified
5.0EPSS 0.013
CVE-1999-0129
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
Published 1999-09-29 · Modified
4.6EPSS 0.006
CVE-1999-0976
Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.
Published 2000-06-02 · Modified
2.1EPSS 0.003