Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2014-3956
Disclosure Date: June 04, 2014 (last updated October 05, 2023)
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
0
Attacker Value
Unknown
CVE-2009-4565
Disclosure Date: January 04, 2010 (last updated October 04, 2023)
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
0
Attacker Value
Unknown
CVE-2009-1490
Disclosure Date: May 05, 2009 (last updated October 04, 2023)
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
0
Attacker Value
Unknown
CVE-2000-0319
Disclosure Date: April 23, 2000 (last updated February 22, 2025)
mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.
0
Attacker Value
Unknown
CVE-1999-0205
Disclosure Date: January 01, 1999 (last updated February 22, 2025)
Denial of service in Sendmail 8.6.11 and 8.6.12.
0
Attacker Value
Unknown
CVE-1999-0204
Disclosure Date: January 01, 1997 (last updated February 22, 2025)
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
0
Attacker Value
Unknown
CVE-1999-0131
Disclosure Date: September 11, 1996 (last updated February 22, 2025)
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
0
Attacker Value
Unknown
CVE-1999-0203
Disclosure Date: August 17, 1995 (last updated February 22, 2025)
In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.
0