Sendmail
Vendor:
First CVE: Oct 1, 1988 · Active for 37 years
14
Total CVEs
More Total CVEs than 91% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sendmail over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 1988
37 years ago
Most Recent CVE
Apr 23, 2000
9,588 days ago
CVE Severity & Scoring
Sendmail14 CVEs
29%
64%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown14 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown14 (100.0%)
User Interaction
None0 (0.0%)
Unknown14 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown14 (100.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-0095HIGH The debug command in Sendmail is enabled, allowing attackers to execute commands as root. | Oct 1, 1988 | 10.0 | 49 | NO | YES |
CVE-1999-0204HIGH Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. | Jan 1, 1997 | 10.0 | 40 | NO | YES |
CVE-1999-0047HIGH MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4. | Jan 28, 1997 | 10.0 | 27 | NO | NO |
CVE-1999-0130HIGH Local users can start Sendmail in daemon mode and gain root privileges. | Nov 16, 1996 | 7.2 | 27 | NO | YES |
CVE-1999-0206HIGH MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access. | Oct 1, 1996 | 10.0 | 25 | NO | NO |
CVE-1999-0203HIGH In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a pro | Aug 17, 1995 | 10.0 | 25 | NO | NO |
CVE-1999-0393MEDIUM Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers. | Jan 1, 1999 | 5.0 | 23 | NO | YES |
CVE-1999-0145HIGH Sendmail WIZ command enabled, allowing root access. | Sep 30, 1993 | 7.2 | 22 | NO | NO |
CVE-1999-0163HIGH In older versions of Sendmail, an attacker could use a pipe character to execute root commands. | Jan 1, 1997 | 7.2 | 20 | NO | NO |
CVE-1999-0131HIGH Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users. | Sep 11, 1996 | 7.2 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
28.6% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Sendmail
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.9.3 | 2 | 3.5 | 1.1% | 0 | 0 |
| 8.9.2 | 1 | 5.0 | 2.4% | 0 | 1 |
| 8.9.1 | 1 | 5.0 | 1.8% | 0 | 0 |
| 8.8.x | 1 | 5.0 | 1.8% | 0 | 0 |
| 8.8.5 | 1 | 5.0 | 1.8% | 0 | 0 |
| 8.8.4 | 2 | 7.5 | 2.5% | 0 | 0 |
| 8.8.3 | 3 | 6.5 | 1.8% | 0 | 0 |
| 8.8.2 | 3 | 5.6 | 1.1% | 0 | 1 |
| 8.8.1 | 4 | 6.7 | 1.3% | 0 | 1 |
| 8.8 | 5 | 6.4 | 1.6% | 0 | 2 |
| 8.7.x | 1 | 5.0 | 1.8% | 0 | 0 |
| 8.7.6 | 1 | 5.0 | 1.8% | 0 | 0 |
| 8.7.5 | 2 | 6.1 | 1.2% | 0 | 0 |
| 8.7.4 | 2 | 6.1 | 1.2% | 0 | 0 |
| 8.7.3 | 2 | 6.1 | 1.2% | 0 | 0 |
| 8.7.2 | 2 | 6.1 | 1.2% | 0 | 0 |
| 8.7.1 | 2 | 6.1 | 1.2% | 0 | 0 |
| 8.7 | 1 | 7.2 | 1.1% | 0 | 1 |
| 8.6.x | 1 | 5.0 | 1.8% | 0 | 0 |
| 8.6.9 | 1 | 10.0 | 8.8% | 0 | 1 |