SMTP vulnerabilities
Showing 151 - 172 of 172 CVEs
- CVE-2001-1349 Published May 28, 2001
Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of service and possibly corrupt the heap and gain privileges via race conditions in signal handlers.
- CVE-2000-0319 Published Apr 23, 2000
mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.
- CVE-1999-1592 Published Dec 31, 1999
Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact. NOTE: this might overlap CVE-1999-0129.
- CVE-1999-1109 Published Dec 22, 1999
Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.
- CVE-1999-0976 Published Dec 7, 1999
Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.
- CVE-1999-0684 Published Apr 19, 1999
Denial of service in Sendmail 8.8.6 in HPUX.
- CVE-1999-0365 Published Feb 4, 1999
The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.
- CVE-1999-0393 Published Jan 1, 1999
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
- CVE-1999-0205 Published Jan 1, 1999
Denial of service in Sendmail 8.6.11 and 8.6.12.
- CVE-1999-0478 Published Dec 1, 1998
Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.
- CVE-1999-0047 Published Jan 28, 1997
MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.
- CVE-1999-0204 Published Jan 1, 1997
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
- CVE-1999-0163 Published Jan 1, 1997
In older versions of Sendmail, an attacker could use a pipe character to execute root commands.
- CVE-1999-0129 Published Dec 3, 1996
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
- CVE-1999-0130 Published Nov 16, 1996
Local users can start Sendmail in daemon mode and gain root privileges.
- CVE-1999-0206 Published Oct 1, 1996
MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.
- CVE-1999-0131 Published Sep 11, 1996
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
- CVE-1999-1309 Published Aug 30, 1996
Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
- CVE-1999-1580 Published Aug 23, 1995
SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.
- CVE-1999-0203 Published Aug 17, 1995
In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.
- CVE-1999-0145 Published Sep 30, 1993
Sendmail WIZ command enabled, allowing root access.
- CVE-1999-0095 Published Oct 1, 1988
The debug command in Sendmail is enabled, allowing attackers to execute commands as root.
Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of service and possibly corrupt the heap and gain privileges via race conditions in signal handlers.
mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.
Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact. NOTE: this might overlap CVE-1999-0129.
Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.
Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.
Denial of service in Sendmail 8.8.6 in HPUX.
The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
Denial of service in Sendmail 8.6.11 and 8.6.12.
Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.
MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
In older versions of Sendmail, an attacker could use a pipe character to execute root commands.
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
Local users can start Sendmail in daemon mode and gain root privileges.
MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.
In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.
Sendmail WIZ command enabled, allowing root access.
The debug command in Sendmail is enabled, allowing attackers to execute commands as root.