Exim

Exim

66 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.8%
  • Veröffentlicht 16.05.2011 18:55:00
  • Zuletzt bearbeitet 16.06.2026 23:29:17

The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.

  • EPSS 0.38%
  • Veröffentlicht 02.02.2011 01:00:06
  • Zuletzt bearbeitet 16.06.2026 23:26:37

The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.

Warnung Medienbericht
  • EPSS 18.11%
  • Veröffentlicht 14.12.2010 16:00:04
  • Zuletzt bearbeitet 16.06.2026 23:24:36

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory direct...

Warnung Medienbericht Exploit
  • EPSS 71.9%
  • Veröffentlicht 14.12.2010 16:00:04
  • Zuletzt bearbeitet 16.06.2026 23:24:36

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted hea...

  • EPSS 0.28%
  • Veröffentlicht 07.06.2010 17:12:48
  • Zuletzt bearbeitet 16.06.2026 23:19:50

transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a...

  • EPSS 0.28%
  • Veröffentlicht 07.06.2010 17:12:48
  • Zuletzt bearbeitet 16.06.2026 23:19:50

transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lock...