Exim

Exim

57 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 17.10.2022 18:15:12
  • Zuletzt bearbeitet 03.11.2025 22:16:00

A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. I...

Exploit
  • EPSS 4.7%
  • Veröffentlicht 07.08.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:15:00

Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

Exploit
  • EPSS 5.74%
  • Veröffentlicht 06.08.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:15:00

Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.

  • EPSS 2.86%
  • Veröffentlicht 10.08.2021 15:15:08
  • Zuletzt bearbeitet 03.11.2025 22:15:50

The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 06.05.2021 13:15:12
  • Zuletzt bearbeitet 21.11.2024 05:57:36

Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.

  • EPSS 0.2%
  • Veröffentlicht 06.05.2021 13:15:09
  • Zuletzt bearbeitet 21.11.2024 05:22:12

Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may allow privilege escalation from any user to root. This occurs because of the interpretation of negative sizes in strncpy.

  • EPSS 3.96%
  • Veröffentlicht 06.05.2021 13:15:09
  • Zuletzt bearbeitet 21.11.2024 05:22:14

Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unau...

  • EPSS 1.67%
  • Veröffentlicht 06.05.2021 13:15:09
  • Zuletzt bearbeitet 21.11.2024 05:22:13

Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between sig->bodyhash.len and b->bh.len; thus, a crafted DKIM-Signature header might lead to a leak of sensitive information from process ...

  • EPSS 4.06%
  • Veröffentlicht 06.05.2021 13:15:09
  • Zuletzt bearbeitet 21.11.2024 05:22:13

Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp_ungetc was only intended to push back characters, but can actually push back non-character error codes such a...

  • EPSS 3.52%
  • Veröffentlicht 06.05.2021 13:15:09
  • Zuletzt bearbeitet 21.11.2024 05:22:13

Exim 4 before 4.94.2 allows Out-of-bounds Read. smtp_setup_msg may disclose sensitive information from process memory to an unauthenticated SMTP client.