Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sendmail sendmail 2.6 vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2016-10034
The setFrom function in the Sendmail adapter in the zend-mail component prior to 2.4.11, 2.5.x, 2.6.x, and 2.7.x prior to 2.7.2, and Zend Framework prior to 2.4.11 might allow remote malicious users to pass extra parameters to the mail command and consequently execute arbitrary c...
Zend Zend Framework
Zend Zend-mail 2.6.2
Zend Zend-mail 2.5.2
Zend Zend-mail 2.5.0
Zend Zend-mail
Zend Zend-mail 2.6.0
Zend Zend-mail 2.7.0
Zend Zend-mail 2.6.1
Zend Zend-mail 2.7.1
Zend Zend-mail 2.5.1
3 EDB exploits
3 Github repositories
NA
CVE-2009-4565
sendmail prior to 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle malicious users to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate C...
Sendmail Sendmail 8.9.2
Sendmail Sendmail 8.11.4
Sendmail Sendmail 8.13.4
Sendmail Sendmail 8.8.8
Sendmail Sendmail 8.11.7
Sendmail Sendmail 8.13.1
Sendmail Sendmail 8.12
Sendmail Sendmail 5
Sendmail Sendmail 2.6
Sendmail Sendmail 8.11.1
Sendmail Sendmail 8.11.0
Sendmail Sendmail 8.13.5
Sendmail Sendmail 8.12.3
Sendmail Sendmail 8.13.8
Sendmail Sendmail 8.11.3
Sendmail Sendmail 2.6.1
Sendmail Sendmail 8.12.8
Sendmail Sendmail 8.6.7
Sendmail Sendmail 8.7.9
Sendmail Sendmail 5.59
Sendmail Sendmail 5.61
Sendmail Sendmail 8.12.9
NA
CVE-2009-1490
Heap-based buffer overflow in Sendmail prior to 8.13.2 allows remote malicious users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
Sendmail Sendmail 2.6.2
Sendmail Sendmail 8.9.2
Sendmail Sendmail 8.12.11
Sendmail Sendmail 8.11.4
Sendmail Sendmail 8.8.8
Sendmail Sendmail 8.11.7
Sendmail Sendmail 2.6.1
Sendmail Sendmail 8.12
Sendmail Sendmail 5
Sendmail Sendmail 2.6
Sendmail Sendmail 8.11.1
Sendmail Sendmail 8.11.0
Sendmail Sendmail 8.12.3
Sendmail Sendmail 8.11.3
Sendmail Sendmail 8.12.8
Sendmail Sendmail 8.6.7
Sendmail Sendmail 8.7.9
Sendmail Sendmail 5.59
Sendmail Sendmail 5.61
Sendmail Sendmail 8.12.9
Sendmail Sendmail 8.9.1
Sendmail Sendmail 3.0.1
1 EDB exploit
NA
CVE-2007-4538
email_in.pl in Bugzilla 2.23.4 up to and including 3.0.0 allows remote malicious users to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters.
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 2.23.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.9
NA
CVE-2003-0681
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
Sendmail Sendmail Switch 2.1.2
Sendmail Sendmail Switch 3.0.2
Sendmail Sendmail Switch 2.2.2
Sendmail Sendmail 2.6.2
Sendmail Sendmail 8.9.2
Sendmail Sendmail Switch 2.1.1
Sendmail Sendmail 8.11.4
Sendmail Sendmail 8.8.8
Sendmail Sendmail 8.12
Sendmail Sendmail 2.6
Sendmail Sendmail 8.11.1
Sendmail Sendmail 8.11.0
Sendmail Sendmail Switch 2.1.3
Sendmail Sendmail 8.12.3
Sendmail Sendmail 8.11.3
Sendmail Sendmail Switch 2.2.1
Sendmail Sendmail 2.6.1
Sendmail Advanced Message Server 1.3
Sendmail Sendmail 8.12.8
Sendmail Sendmail 8.12.9
Sendmail Sendmail 8.9.1
Sendmail Sendmail Pro 8.9.2
1 EDB exploit
NA
CVE-2003-0694
The prescan function in Sendmail 8.12.9 allows remote malicious users to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Sendmail Sendmail Switch 2.1.2
Sendmail Sendmail Switch 3.0.2
Sendmail Sendmail Switch 2.2.2
Sendmail Sendmail 2.6.2
Sendmail Sendmail 8.9.2
Sendmail Sendmail Switch 2.1.1
Sendmail Sendmail 8.11.4
Sendmail Sendmail 8.8.8
Sendmail Sendmail 8.12
Sgi Irix 6.5.17f
Sendmail Sendmail 2.6
Sendmail Sendmail 8.11.1
Sendmail Sendmail 8.11.0
Sendmail Sendmail Switch 2.1.3
Sendmail Sendmail 8.12.3
Sendmail Sendmail 8.11.3
Sendmail Sendmail Switch 2.2.1
Sendmail Sendmail 2.6.1
Sendmail Advanced Message Server 1.3
Sendmail Sendmail 8.12.8
Sgi Irix 6.5.18f
Sgi Irix 6.5.19f
1 Github repository
NA
CVE-2003-0161
The prescan() function in the address parser (parseaddr.c) in Sendmail prior to 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" co...
Sendmail Sendmail Switch 2.1.2
Sendmail Sendmail Switch 3.0.2
Sendmail Sendmail Switch 2.2.2
Sendmail Sendmail 2.6.2
Sendmail Sendmail 8.9.2
Sendmail Sendmail Switch 2.1.1
Sendmail Sendmail 8.11.4
Sendmail Sendmail 8.12
Sendmail Sendmail 2.6
Sendmail Sendmail 8.11.1
Sendmail Sendmail 8.11.0
Sendmail Sendmail Switch 2.1.3
Sendmail Sendmail 8.12.3
Sendmail Sendmail 8.11.3
Sendmail Sendmail Switch 2.2.1
Sendmail Sendmail 2.6.1
Sendmail Sendmail 8.12.8
Sendmail Sendmail 8.9.1
Sendmail Sendmail Switch 2.2
Sendmail Sendmail 8.10.2
Sendmail Sendmail 8.12.4
Sendmail Sendmail 8.9.0
2 EDB exploits
1 Github repository
NA
CVE-2002-1337
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote malicious users to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
Sendmail Sendmail
Netbsd Netbsd 1.5.3
Netbsd Netbsd 1.6
Hp Hp-ux 11.11
Netbsd Netbsd 1.5
Windriver Bsdos 4.2
Sun Sunos 5.7
Sun Sunos 5.8
Gentoo Linux 1.4
Hp Hp-ux 11.00
Windriver Bsdos 5.0
Netbsd Netbsd 1.5.1
Hp Hp-ux 11.0.4
Oracle Solaris 8
Hp Hp-ux 11.22
Netbsd Netbsd 1.5.2
Oracle Solaris 9
Hp Alphaserver Sc
Hp Hp-ux 10.20
Windriver Platform Sa 1.0
Hp Hp-ux 10.10
Windriver Bsdos 4.3.1
3 EDB exploits
1 Github repository
NA
CVE-1999-0098
Buffer overflow in SMTP HELO command in Sendmail allows a remote malicious user to hide activities.
Apple Appleshare -
Pmail Mercury Mail Server -
Seattlelab Slmail 2.6
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started