Exim

Exim

66 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 24.07.2026 04:37:46
  • Zuletzt bearbeitet 17.08.2026 19:06:33

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

  • EPSS 0.26%
  • Veröffentlicht 24.07.2026 04:32:08
  • Zuletzt bearbeitet 17.08.2026 19:04:18

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

  • EPSS 0.26%
  • Veröffentlicht 30.05.2026 01:50:42
  • Zuletzt bearbeitet 22.07.2026 06:10:00

Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.

Medienbericht
  • EPSS 1.23%
  • Veröffentlicht 12.05.2026 00:00:00
  • Zuletzt bearbeitet 28.05.2026 18:46:27

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byt...

Medienbericht
  • EPSS 0.37%
  • Veröffentlicht 30.04.2026 00:00:00
  • Zuletzt bearbeitet 01.05.2026 19:17:51

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memo...

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 30.04.2026 00:00:00
  • Zuletzt bearbeitet 01.05.2026 17:44:15

In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an ...

Medienbericht
  • EPSS 0.32%
  • Veröffentlicht 30.04.2026 00:00:00
  • Zuletzt bearbeitet 01.05.2026 17:51:06

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 30.04.2026 00:00:00
  • Zuletzt bearbeitet 01.05.2026 18:16:15

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

  • EPSS 0.46%
  • Veröffentlicht 14.12.2025 04:00:24
  • Zuletzt bearbeitet 22.12.2025 19:15:45

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

  • EPSS 0.52%
  • Veröffentlicht 27.03.2025 00:00:00
  • Zuletzt bearbeitet 30.09.2025 21:52:55

A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.