Where
-Infinity
0

Vendor Risk Score

See how eric allman compares to other vendors in security performance

View Risk Score →
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P

Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Denial of service in Sendmail 8.6.11 and 8.6.12.

First published (updated )
Severity
7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P

Vacation program allows command execution by remote users through a sendmail command.

First published (updated )
Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.

First published (updated )
Severity
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C

In older versions of Sendmail, an attacker could use a pipe character to execute root commands.

First published (updated )
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.

First published (updated )
Severity
4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P

Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.

First published (updated )
Severity
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C

Local users can start Sendmail in daemon mode and gain root privileges.

First published (updated )
Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.

First published (updated )
Severity
7.2
Buffer Overflow
AV:L/AC:L/Au:N/C:C/I:C/A:C

Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.

First published (updated )
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.

First published (updated )
Severity
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C

Sendmail WIZ command enabled, allowing root access.

First published (updated )
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

The debug command in Sendmail is enabled, allowing attackers to execute commands as root.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203