LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2003-0161

CVE-2003-0161

CVSS 10 · HIGH

Summary

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.

CVSS 2.0 breakdown

Base score10 (HIGH)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Attack vectorNETWORK
Attack complexityLOW
ConfidentialityCOMPLETE
IntegrityCOMPLETE
AvailabilityCOMPLETE

Affected products

Sendmail sendmailSendmail sendmail switchCompaq tru64Hp hp-uxHp hp-ux series 700Hp hp-ux series 800Hp sisSun solarisSun sunos
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.

Scroll to Top