This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:sendmail:sendmail:8.12:beta7
Detail
VendorSendmailFirst view 2001-05-28
ProductSendmailLast view 2010-01-04
Version8.12TypeApplication
Edition 
Language 
Updatebeta7 
 
CPE Productcpe:/a:sendmail:sendmail

Activity : Yearly

Related : CVE

 DateAlertAccess VectorAccess ComplexityAuthentification
7.52010-01-04CVE-2009-4565NetworkLowNone Requ...
52009-05-05CVE-2009-1490NetworkLowNone Requ...
52006-08-28CVE-2006-4434NetworkLowNone Requ...
52006-06-07CVE-2006-1173NetworkLowNone Requ...
52005-06-29CVE-2005-2070NetworkLowNone Requ...
Hide | Show 8 More...
 DateAlertAccess VectorAccess ComplexityAuthentification
102003-10-06CVE-2003-0694NetworkLowNone Requ...
7.52003-10-06CVE-2003-0681NetworkLowNone Requ...
102003-04-02CVE-2003-0161NetworkLowNone Requ...
102003-03-07CVE-2002-1337NetworkLowNone Requ...
7.52002-12-31CVE-2002-2261NetworkLowNone Requ...
2.12002-12-31CVE-2002-1827LocalLowNone Requ...
4.62001-09-20CVE-2001-0653LocalLowNone Requ...
3.72001-05-28CVE-2001-1349LocalHighNone Requ...

CWE : Common Weakness Enumeration

%idName
40% (2)CWE-399Resource Management Errors
20% (1)CWE-310Cryptographic Issues
20% (1)CWE-264Permissions, Privileges, and Access Controls
20% (1)CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer

CAPEC : Common Attack Pattern Enumeration & Classificatio

idName
CAPEC-2Inducing Account Lockout
CAPEC-8Buffer Overflow in an API Call
CAPEC-9Buffer Overflow in Local Command-Line Utilities
CAPEC-10Buffer Overflow via Environment Variables
CAPEC-14Client-side Injection-induced Buffer Overflow
Hide | Show 13 More...
idName
CAPEC-24Filter Failure through Buffer Overflow
CAPEC-42MIME Conversion
CAPEC-44Overflow Binary Resource File
CAPEC-45Buffer Overflow via Symbolic Links
CAPEC-46Overflow Variables and Tags
CAPEC-47Buffer Overflow via Parameter Expansion
CAPEC-67String Format Overflow in syslog()
CAPEC-82Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Servi...
CAPEC-92Forced Integer Overflow
CAPEC-100Overflow Buffers
CAPEC-123Buffer Attacks
CAPEC-147XML Ping of Death
CAPEC-228Resource Depletion through DTD Injection in a SOAP Message

Oval Markup Language : Definitions

OvalIDName
oval:org.mitre.oval:def:2222Sendmail Address Processor Buffer Overflow
oval:org.mitre.oval:def:8512HP-UX Running sendmail, Remote Denial of Service (DoS)
oval:org.mitre.oval:def:6892HP-UX Running sendmail, Remote Denial of Service (DoS)
oval:org.mitre.oval:def:595Potential BO in Ruleset Parsing for Sendmail
oval:org.mitre.oval:def:3606Sendmail Ruleset Parsing Buffer Overflow
Hide | Show 6 More...
idName
oval:org.mitre.oval:def:603Sendmail BO in prescan Function
oval:org.mitre.oval:def:572Sendmail BO in Prescan Function
oval:org.mitre.oval:def:2975Sendmail prescan function Buffer Overflow
oval:org.mitre.oval:def:11253Sendmail before 8.13.7 allows remote attackers to cause a denial of service v...
oval:org.mitre.oval:def:11822HP-UX Running sendmail with STARTTLS Enabled, Remote Unauthorized Access.
oval:org.mitre.oval:def:10255sendmail before 8.14.4 does not properly handle a '\0' character in a Common ...

Open Source Vulnerability Database (OSVDB)

idDescription
62373Sendmail X.509 Certificate Null Character MiTM Spoofing Weakness
60140Sendmail Spoofed DNS Hostname check_relay Function Bypass
59769Sendmail Multiple Configuration File Lock Local DoS
54669Sendmail Mail X-Header Handling Remote Overflow
28193Sendmail Header Processing Overflow DoS
Hide | Show 7 More...
idDescription
26197Sendmail Multi-Part MIME Message Handling DoS
17562ClamAV clamav-milter Remote Connection Hold DoS
8294Sendmail NOCHAR Control Value prescan Overflow
5429Sendmail Insecure Signal Handling Local DoS
4502Sendmail headers.c crackaddr Function Address Field Handling Remote Overflow
2577Sendmail prescan() Function Remote Overflow
605Sendmail -d category Value Local Overflow

Metasploit Exploits

idDescription
2003-09-17Sendmail SMTP Address prescan <= 8.12.8 Memory Corruption