peter bassill · operator
$ cve CVE-2002-1337 JSON

CVE-2002-1337 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 72.6% (pctl 99)

Patch early

A public exploit exists.

Description

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS72.64% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploityes
Published2003-03-07
Last modified2026-06-16

Affected (9)

VendorProduct
gentoolinux
hpalphaserver sc
hphp-ux
netbsdnetbsd
oraclesolaris
sendmailsendmail
sunsunos
windriverbsdos
windriverplatform sa

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD