CVE-2003-0694

CRITICAL

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

Affects 18 products across 11 vendors.

BCS7.98
CVSS 2.010.0
EPSS66.2%
Percentile99th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2003. A critical vulnerability affects Apple systems (CVE-2003-0694). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2003-GLOBAL-000388-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2003-0694?
This vulnerability was disclosed in 2003. A critical vulnerability affects Apple systems (CVE-2003-0694). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2003-0694?
CVE-2003-0694 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 66.2%.
Is CVE-2003-0694 actively exploited?
No confirmed active exploitation of CVE-2003-0694 as of 2026-05-30.
How do I remediate CVE-2003-0694?
Priority: MEDIUM. Advisory: http://www.cert.org/advisories/CA-2003-25.html
What systems are affected by CVE-2003-0694?
CVE-2003-0694 affects: Apple, Apple, Compaq, Freebsd, Gentoo, Hp, Ibm, Netbsd.
Vulnerability Details
CVE IDCVE-2003-0694
BSIDBS-2003-GLOBAL-000388-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2003-10-06
Last Modified2026-04-16
ICS Relevance0%
SourceNVD
Official Description

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Apple Mac Os X Server
Apple Mac Os X
Compaq Tru64
Freebsd Freebsd
Gentoo Linux
Hp Hp-Ux
Ibm Aix
Netbsd Netbsd
Sendmail Sendmail Pro
Sendmail Sendmail
Sendmail Sendmail Switch
Sendmail Advanced Message Server
Sgi Irix
Sun Sunos
Sun Solaris
Turbolinux Turbolinux Server
Turbolinux Turbolinux Workstation
Turbolinux Turbolinux Advanced Server
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 8338 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash6d28680db6d90cdf5ed54db42af6baf99c51edaab300b85ac1a4eed8e13706708e29775ee34b01167352690a3c5ac13c172a463fc543b066f8229728b94d57b2
Related CVEs affecting Apple
CVE-2007-2387 10.0 Apple Xserve Lights-Out Management before Firmware Update 1.0 on Intel hardwa... CVE-2003-0426 10.0 The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f s... CVE-2003-0502 10.0 Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attacke... CVE-2013-3324 10.0 Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows... CVE-2003-1009 10.0 Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple...
View all Apple CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →