CVE-2026-94057
- EPSS 0.16%
- Veröffentlicht 19.09.2026 22:55:00
- Zuletzt bearbeitet 24.09.2026 20:40:10
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
CVE-2026-94056
- EPSS 0.25%
- Veröffentlicht 19.09.2026 22:52:43
- Zuletzt bearbeitet 24.09.2026 20:45:30
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
CVE-2026-94055
- EPSS 0.31%
- Veröffentlicht 19.09.2026 22:48:57
- Zuletzt bearbeitet 24.09.2026 20:45:59
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
CVE-2026-94054
- EPSS 0.27%
- Veröffentlicht 19.09.2026 22:46:24
- Zuletzt bearbeitet 24.09.2026 20:47:34
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
CVE-2026-66141
- EPSS 0.1%
- Veröffentlicht 24.07.2026 04:37:46
- Zuletzt bearbeitet 17.08.2026 19:06:33
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
CVE-2026-66140
- EPSS 0.26%
- Veröffentlicht 24.07.2026 04:32:08
- Zuletzt bearbeitet 17.08.2026 19:04:18
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
CVE-2026-48840
- EPSS 0.26%
- Veröffentlicht 30.05.2026 01:50:42
- Zuletzt bearbeitet 22.07.2026 06:10:00
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
CVE-2026-45185
- EPSS 1.23%
- Veröffentlicht 12.05.2026 00:00:00
- Zuletzt bearbeitet 28.05.2026 18:46:27
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byt...
CVE-2026-40687
- EPSS 0.37%
- Veröffentlicht 30.04.2026 00:00:00
- Zuletzt bearbeitet 01.05.2026 19:17:51
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memo...
CVE-2026-40684
- EPSS 0.36%
- Veröffentlicht 30.04.2026 00:00:00
- Zuletzt bearbeitet 01.05.2026 18:16:15
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.