Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sendmail

First CVE: Aug 23, 1995Active for: 31 yearsTotal CVEs: 33
47.0
VTI Score
High

Sendmail is a foundational mail-transfer agent that, despite a narrow product portfolio, holds a prominent position in email infrastructure and has been a fixture in enterprise and internet-connected systems for decades. The vendor's vulnerability profile centers on its core mail-server products and related messaging platforms, where the recurring weakness classes reflect the parsing and buffer-management demands of SMTP protocol handling: classic buffer overflows, input-validation flaws, certificate-validation issues, and information-exposure conditions recur across its disclosures. Vulnerabilities in this vendor have a strong, recurring history of public exploit availability, making patches operationally critical despite the absence of broad critical-severity clustering. Defenders should prioritize Sendmail instances in network inventory and treat security updates as high-impact; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sendmail over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 23, 1995
30 years ago
Most Recent CVE
Dec 24, 2023
943 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2002-1337HIGH
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a
Mar 7, 200310.080NOYES
CVE-2003-0694HIGH
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Oct 6, 200310.073NOYES
CVE-2003-0161HIGH
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length
Apr 2, 200310.063NOYES
CVE-2006-0058HIGH
Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp
Mar 22, 20067.645NOYES
CVE-2003-0681HIGH
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has
Oct 6, 20037.545NOYES
CVE-2009-1490MEDIUM
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, a
May 5, 20095.027NOYES
CVE-1999-1109MEDIUM
Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to pro
Dec 22, 19995.025NOYES
CVE-2009-4565HIGH
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrar
Jan 4, 20107.524NONO
CVE-2021-3618HIGH
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or
Mar 23, 20227.423NONO
CVE-2003-0308HIGH
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksen
May 15, 20037.223NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
15%
36%
48%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (9.1%)
Unknown30 (90.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (6.1%)
High1 (3.0%)
Unknown30 (90.9%)
User Interaction
None3 (9.1%)
Unknown30 (90.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (9.1%)
Unknown30 (90.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
27.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sendmail.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sendmail — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sendmail's Products

View all 3 CNAs →

Top CWEs