Sendmail

Vendor:

First CVE: Oct 1, 1988 · Active for 37 years

14
Total CVEs
More Total CVEs than 91% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sendmail over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 1988
37 years ago
Most Recent CVE
Apr 23, 2000
9,588 days ago

CVE Severity & Scoring

Sendmail14 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown14 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown14 (100.0%)
User Interaction
None0 (0.0%)
Unknown14 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown14 (100.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The debug command in Sendmail is enabled, allowing attackers to execute commands as root.
Oct 1, 198810.049NOYES
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
Jan 1, 199710.040NOYES
MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.
Jan 28, 199710.027NONO
Local users can start Sendmail in daemon mode and gain root privileges.
Nov 16, 19967.227NOYES
MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.
Oct 1, 199610.025NONO
In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a pro
Aug 17, 199510.025NONO
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
Jan 1, 19995.023NOYES
Sendmail WIZ command enabled, allowing root access.
Sep 30, 19937.222NONO
In older versions of Sendmail, an attacker could use a pipe character to execute root commands.
Jan 1, 19977.220NONO
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
Sep 11, 19967.220NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
28.6% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Sendmail

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.9.323.51.1%00
8.9.215.02.4%01
8.9.115.01.8%00
8.8.x15.01.8%00
8.8.515.01.8%00
8.8.427.52.5%00
8.8.336.51.8%00
8.8.235.61.1%01
8.8.146.71.3%01
8.856.41.6%02
8.7.x15.01.8%00
8.7.615.01.8%00
8.7.526.11.2%00
8.7.426.11.2%00
8.7.326.11.2%00
8.7.226.11.2%00
8.7.126.11.2%00
8.717.21.1%01
8.6.x15.01.8%00
8.6.9110.08.8%01