Sendmail is a foundational mail-transfer agent that, despite a narrow product portfolio, holds a prominent position in email infrastructure and has been a fixture in enterprise and internet-connected systems for decades. The vendor's vulnerability profile centers on its core mail-server products and related messaging platforms, where the recurring weakness classes reflect the parsing and buffer-management demands of SMTP protocol handling: classic buffer overflows, input-validation flaws, certificate-validation issues, and information-exposure conditions recur across its disclosures. Vulnerabilities in this vendor have a strong, recurring history of public exploit availability, making patches operationally critical despite the absence of broad critical-severity clustering. Defenders should prioritize Sendmail instances in network inventory and treat security updates as high-impact; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sendmail over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1337HIGH Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a | Mar 7, 2003 | 10.0 | 80 | NO | YES |
CVE-2003-0694HIGH The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | Oct 6, 2003 | 10.0 | 73 | NO | YES |
CVE-2003-0161HIGH The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length | Apr 2, 2003 | 10.0 | 63 | NO | YES |
CVE-2006-0058HIGH Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp | Mar 22, 2006 | 7.6 | 45 | NO | YES |
CVE-2003-0681HIGH A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has | Oct 6, 2003 | 7.5 | 45 | NO | YES |
CVE-2009-1490MEDIUM Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, a | May 5, 2009 | 5.0 | 27 | NO | YES |
CVE-1999-1109MEDIUM Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to pro | Dec 22, 1999 | 5.0 | 25 | NO | YES |
CVE-2009-4565HIGH sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrar | Jan 4, 2010 | 7.5 | 24 | NO | NO |
CVE-2021-3618HIGH ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or | Mar 23, 2022 | 7.4 | 23 | NO | NO |
CVE-2003-0308HIGH The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksen | May 15, 2003 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sendmail.
Media articles that mention a CVE ID that affects a product developed by Sendmail — matched by CVE ID, not by vendor name.