Vulnerabilities
Vulnerable Software
Sendmail:  >> Sendmail  >> 5.61  Security Vulnerabilities
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVSS Score
7.5
EPSS Score
0.01
Published
2010-01-04
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
CVSS Score
5.0
EPSS Score
0.183
Published
2009-05-05
SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.
CVSS Score
7.2
EPSS Score
0.001
Published
1995-08-23


Contact Us

Shodan ® - All rights reserved