Procmail is a widely embedded mail-filtering and delivery utility with a narrow product scope but deep presence in legacy email infrastructure, where it has processed message routing and sorting across many server deployments. The observed vulnerability signal centers on memory-handling issues and input-boundary conditions inherent to the mail-processing context; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Procmail over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16844CRITICAL Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly exe | Nov 16, 2017 | 9.8 | 38 | NO | NO |
CVE-2014-3618HIGH Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted e | Sep 8, 2014 | 7.5 | 22 | NO | NO |
CVE-1999-0439HIGH Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file. | Apr 5, 1999 | 7.5 | 20 | NO | NO |
CVE-2001-0905MEDIUM Race condition in signal handling of procmail 3.20 and earlier, when running setuid, allows local users to cause a denial of service or gain root privileges by sending a signal whi | Oct 18, 2001 | 6.2 | 17 | NO | NO |
A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail. | Apr 5, 1999 | 1.2 | 10 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Procmail.
Media articles that mention a CVE ID that affects a product developed by Procmail — matched by CVE ID, not by vendor name.