Eric Allman
eric_allman
15 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (15)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that i...Show more |
Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail. |
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers. |
Denial of service in Sendmail 8.6.11 and 8.6.12. |
5Eric Allman FreebsdHp+2 more7Aix FreebsdHp Ux+4 moreApr 16, 2026 Nov 16, 1998 N/A· v4 N/A· v3 7.5 HIGH· v2 Vacation program allows command execution by remote users through a sendmail command. |
3Bsdi CalderaEric Allman3Bsd Os OpenlinuxSendmailApr 16, 2026 Jan 28, 1997 N/A· v4 N/A· v3 10.0 HIGH· v2 MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4. |
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. |
In older versions of Sendmail, an attacker could use a pipe character to execute root commands. |
7Bsdi Eric AllmanFreebsd+4 more9Aix Bsd OsFreebsd+6 moreApr 16, 2026 Dec 3, 1996 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file. |
7Bsdi CalderaEric Allman+4 more7Aix Bsd OsFreebsd+4 moreApr 16, 2026 Nov 16, 1996 N/A· v4 N/A· v3 7.2 HIGH· v2 Local users can start Sendmail in daemon mode and gain root privileges. |
MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access. |
8Bsdi DigitalEric Allman+5 more9Aix Bsd OsFreebsd+6 moreApr 16, 2026 Sep 11, 1996 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users. |
In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program. |
Sendmail WIZ command enabled, allowing root access. |
The debug command in Sendmail is enabled, allowing attackers to execute commands as root. |