Exim

Exim

57 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.53%
  • Veröffentlicht 05.10.2011 02:56:24
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM...

  • EPSS 0.72%
  • Veröffentlicht 16.05.2011 18:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.

  • EPSS 0.12%
  • Veröffentlicht 02.02.2011 01:00:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.

Warnung Medienbericht
  • EPSS 4.02%
  • Veröffentlicht 14.12.2010 16:00:04
  • Zuletzt bearbeitet 22.10.2025 01:15:39

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory direct...

Warnung Medienbericht Exploit
  • EPSS 61.46%
  • Veröffentlicht 14.12.2010 16:00:04
  • Zuletzt bearbeitet 22.10.2025 01:15:39

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted hea...

  • EPSS 0.09%
  • Veröffentlicht 07.06.2010 17:12:48
  • Zuletzt bearbeitet 11.04.2025 00:51:21

transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a...

  • EPSS 0.07%
  • Veröffentlicht 07.06.2010 17:12:48
  • Zuletzt bearbeitet 11.04.2025 00:51:21

transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lock...