VYPR
Vendor

Eric Allman

Sign in to watch
Products
2
CVEs
15
Across products
48
Status
Private

Products

2

Recent CVEs

15
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-1999-00950.050.22Oct 1, 1988The debug command in Sendmail is enabled, allowing attackers to execute commands as root.
CVE-1999-03930.030.06Jan 1, 1999Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
CVE-1999-02040.030.03Jan 1, 1997Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
CVE-1999-01300.030.01Nov 16, 1996Local users can start Sendmail in daemon mode and gain root privileges.
CVE-2000-03190.000.01Apr 23, 2000mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.
CVE-1999-09760.000.00Dec 7, 1999Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.
CVE-1999-02050.000.01Jan 1, 1999Denial of service in Sendmail 8.6.11 and 8.6.12.
CVE-1999-00570.000.05Nov 16, 1998Vacation program allows command execution by remote users through a sendmail command.
CVE-1999-00470.000.02Jan 28, 1997MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.
CVE-1999-01630.000.00Jan 1, 1997In older versions of Sendmail, an attacker could use a pipe character to execute root commands.
CVE-1999-01290.000.00Dec 3, 1996Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
CVE-1999-02060.000.01Oct 1, 1996MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.
CVE-1999-01310.000.00Sep 11, 1996Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
CVE-1999-02030.000.00Aug 17, 1995In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.
CVE-1999-01450.000.01Sep 30, 1993Sendmail WIZ command enabled, allowing root access.