CVE-2023-42114
- EPSS 28.08%
- Veröffentlicht 03.05.2024 03:15:49
- Zuletzt bearbeitet 04.11.2025 20:16:48
Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability....
CVE-2023-51766
- EPSS 1.08%
- Veröffentlicht 24.12.2023 06:15:07
- Zuletzt bearbeitet 04.11.2025 19:16:21
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mecha...
CVE-2022-3620
- EPSS 0.8%
- Veröffentlicht 20.10.2022 20:15:09
- Zuletzt bearbeitet 23.05.2025 18:29:51
A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. The manipulation leads to use after free. The attack may be initiated remotely. The ...
CVE-2022-3559
- EPSS 3.97%
- Veröffentlicht 17.10.2022 18:15:12
- Zuletzt bearbeitet 03.11.2025 22:16:00
A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. I...
CVE-2022-37452
- EPSS 3.8%
- Veröffentlicht 07.08.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:15:00
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
CVE-2022-37451
- EPSS 3.24%
- Veröffentlicht 06.08.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:15:00
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
CVE-2021-38371
- EPSS 2%
- Veröffentlicht 10.08.2021 15:15:08
- Zuletzt bearbeitet 03.11.2025 22:15:50
The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.
CVE-2021-27216
- EPSS 0.98%
- Veröffentlicht 06.05.2021 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:57:36
Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.
CVE-2020-28020
- EPSS 7.94%
- Veröffentlicht 06.05.2021 13:15:09
- Zuletzt bearbeitet 21.11.2024 05:22:13
Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by leveraging the mishandling of continuation lines during header-length restriction.
CVE-2020-28026
- EPSS 9.25%
- Veröffentlicht 06.05.2021 13:15:09
- Zuletzt bearbeitet 21.11.2024 05:22:14
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly allow unau...