Exim

Exim

70 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 19.09.2026 22:55:00
  • Zuletzt bearbeitet 24.09.2026 20:40:10

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

  • EPSS 0.25%
  • Veröffentlicht 19.09.2026 22:52:43
  • Zuletzt bearbeitet 24.09.2026 20:45:30

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

  • EPSS 0.31%
  • Veröffentlicht 19.09.2026 22:48:57
  • Zuletzt bearbeitet 24.09.2026 20:45:59

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

  • EPSS 0.27%
  • Veröffentlicht 19.09.2026 22:46:24
  • Zuletzt bearbeitet 24.09.2026 20:47:34

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

  • EPSS 0.1%
  • Veröffentlicht 24.07.2026 04:37:46
  • Zuletzt bearbeitet 17.08.2026 19:06:33

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

  • EPSS 0.26%
  • Veröffentlicht 24.07.2026 04:32:08
  • Zuletzt bearbeitet 17.08.2026 19:04:18

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

  • EPSS 0.26%
  • Veröffentlicht 30.05.2026 01:50:42
  • Zuletzt bearbeitet 22.07.2026 06:10:00

Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.

Medienbericht
  • EPSS 1.23%
  • Veröffentlicht 12.05.2026 00:00:00
  • Zuletzt bearbeitet 28.05.2026 18:46:27

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byt...

Medienbericht
  • EPSS 0.37%
  • Veröffentlicht 30.04.2026 00:00:00
  • Zuletzt bearbeitet 01.05.2026 19:17:51

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memo...

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 30.04.2026 00:00:00
  • Zuletzt bearbeitet 01.05.2026 18:16:15

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.