← All CVEs

CVE-2002-1337

high · 10

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

10
CVSS
72.6%
EPSS (exploit prob.)
99th
EPSS percentile
2003-03-07
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-120

Affected products

VendorProductAffected versions
sendmailsendmail< 8.9.3
sendmailsendmail>= 8.10.0, < 8.11.6
sendmailsendmail>= 8.12.0, < 8.12.8
hpalphaserver_scall versions
gentoolinux1.4
gentoolinux1.4
hphp-ux10.10
hphp-ux10.20
hphp-ux11.00
hphp-ux11.0.4
hphp-ux11.11
hphp-ux11.22
netbsdnetbsd1.5
netbsdnetbsd1.5.1
netbsdnetbsd1.5.2
netbsdnetbsd1.5.3
netbsdnetbsd1.6
oraclesolaris2.6
oraclesolaris7.0
oraclesolaris8
oraclesolaris9
sunsunosall versions
sunsunos5.7
sunsunos5.8
windriverbsdos4.2
windriverbsdos4.3.1
windriverbsdos5.0
windriverplatform_sa1.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-1337