Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."
Conclusion & alert: CVE-2006-4434 is rated Moderate Risk (59.6/100): CVSS High severity, with high exploitation likelihood (EPSS 7.03%, 91th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-12-28 | 9.29% | 7.03% | -2.27% |
| 2 | 2025-12-27 | 7.03% | 9.29% | +2.27% |
| 3 | 2025-10-28 | — | 7.03% | — |
Full EPSS history (22 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2006-4434: no source package rows; 0 state rows across 0 repos (none); fixed 0, open 0. | https://security.alpinelinux.org/vuln/CVE-2006-4434 |
debian
|
medium | CVE-2006-4434 medium priority: Debian including 1 source packages (sendmail), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2006-4434 |
redhat
|
— | — | https://access.redhat.com/security/cve/CVE-2006-4434 |
ubuntu
|
medium | CVE-2006-4434 medium priority: Ubuntu including 1 source packages (sendmail), 9 status rows across 9 suites (dapper, edgy, feisty, gutsy, hardy, intrepid, jaunty, karmic, upstream): released 8, ignored 1. | https://ubuntu.com/security/CVE-2006-4434 |
This flaw causes a crash but does not result in a denial of service against Sendmail and is therefore not a security issue.