This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:sendmail:sendmail:8.12:beta5
Detail
VendorSendmailFirst view 2001-09-20
ProductSendmailLast view 2010-01-04
Version8.12TypeApplication
Edition 
Language 
Updatebeta5 
 
CPE Productcpe:/a:sendmail:sendmail

Activity : Yearly

Related : CVE

 DateAlertAccess VectorAccess ComplexityAuthentification
7.52010-01-04CVE-2009-4565NetworkLowNone Requ...
52009-05-05CVE-2009-1490NetworkLowNone Requ...
52006-08-28CVE-2006-4434NetworkLowNone Requ...
52006-06-07CVE-2006-1173NetworkLowNone Requ...
52005-06-29CVE-2005-2070NetworkLowNone Requ...
Hide | Show 7 More...
 DateAlertAccess VectorAccess ComplexityAuthentification
102003-10-06CVE-2003-0694NetworkLowNone Requ...
7.52003-10-06CVE-2003-0681NetworkLowNone Requ...
102003-04-02CVE-2003-0161NetworkLowNone Requ...
102003-03-07CVE-2002-1337NetworkLowNone Requ...
7.52002-12-31CVE-2002-2261NetworkLowNone Requ...
2.12002-12-31CVE-2002-1827LocalLowNone Requ...
4.62001-09-20CVE-2001-0653LocalLowNone Requ...

CWE : Common Weakness Enumeration

%idName
40% (2)CWE-399Resource Management Errors
20% (1)CWE-310Cryptographic Issues
20% (1)CWE-264Permissions, Privileges, and Access Controls
20% (1)CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer

CAPEC : Common Attack Pattern Enumeration & Classificatio

idName
CAPEC-2Inducing Account Lockout
CAPEC-8Buffer Overflow in an API Call
CAPEC-9Buffer Overflow in Local Command-Line Utilities
CAPEC-10Buffer Overflow via Environment Variables
CAPEC-14Client-side Injection-induced Buffer Overflow
Hide | Show 13 More...
idName
CAPEC-24Filter Failure through Buffer Overflow
CAPEC-42MIME Conversion
CAPEC-44Overflow Binary Resource File
CAPEC-45Buffer Overflow via Symbolic Links
CAPEC-46Overflow Variables and Tags
CAPEC-47Buffer Overflow via Parameter Expansion
CAPEC-67String Format Overflow in syslog()
CAPEC-82Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Servi...
CAPEC-92Forced Integer Overflow
CAPEC-100Overflow Buffers
CAPEC-123Buffer Attacks
CAPEC-147XML Ping of Death
CAPEC-228Resource Depletion through DTD Injection in a SOAP Message

Oval Markup Language : Definitions

OvalIDName
oval:org.mitre.oval:def:2222Sendmail Address Processor Buffer Overflow
oval:org.mitre.oval:def:8512HP-UX Running sendmail, Remote Denial of Service (DoS)
oval:org.mitre.oval:def:6892HP-UX Running sendmail, Remote Denial of Service (DoS)
oval:org.mitre.oval:def:595Potential BO in Ruleset Parsing for Sendmail
oval:org.mitre.oval:def:3606Sendmail Ruleset Parsing Buffer Overflow
Hide | Show 6 More...
idName
oval:org.mitre.oval:def:603Sendmail BO in prescan Function
oval:org.mitre.oval:def:572Sendmail BO in Prescan Function
oval:org.mitre.oval:def:2975Sendmail prescan function Buffer Overflow
oval:org.mitre.oval:def:11253Sendmail before 8.13.7 allows remote attackers to cause a denial of service v...
oval:org.mitre.oval:def:11822HP-UX Running sendmail with STARTTLS Enabled, Remote Unauthorized Access.
oval:org.mitre.oval:def:10255sendmail before 8.14.4 does not properly handle a '\0' character in a Common ...

Open Source Vulnerability Database (OSVDB)

idDescription
62373Sendmail X.509 Certificate Null Character MiTM Spoofing Weakness
60140Sendmail Spoofed DNS Hostname check_relay Function Bypass
59769Sendmail Multiple Configuration File Lock Local DoS
54669Sendmail Mail X-Header Handling Remote Overflow
28193Sendmail Header Processing Overflow DoS
Hide | Show 6 More...
idDescription
26197Sendmail Multi-Part MIME Message Handling DoS
17562ClamAV clamav-milter Remote Connection Hold DoS
8294Sendmail NOCHAR Control Value prescan Overflow
4502Sendmail headers.c crackaddr Function Address Field Handling Remote Overflow
2577Sendmail prescan() Function Remote Overflow
605Sendmail -d category Value Local Overflow

Metasploit Exploits

idDescription
2003-09-17Sendmail SMTP Address prescan <= 8.12.8 Memory Corruption