Exim kayıtları
exim üreticisine ait 71 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 5 · %7
- Silahlaştırılmış
- 6 · %8,5
- Pre-auth RCE
- 18
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- 1364 gün
Tekrar eden sınıflar
- CWE-787 Out-of-bounds Write11
- CWE-125 Out-of-bounds Read6
- CWE-416 Use After Free5
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')3
- CWE-20 Improper Input Validation3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
71 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2019-10149Silahlaştırılmış | A flaw was found in Exim versions 4.87 to 4.91 (inclusive).exim · exim · CWE-78 | Kritik9,8 | KEV | %100,0 | 5 Haz 2019 |
94Hemen | CVE-2018-6789Silahlaştırılmış | An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.exim · exim · CWE-120 | Kritik9,8 | KEV | %82,1 | 8 Şub 2018 |
91Hemen | CVE-2010-4344Silahlaştırılmış | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code exim · exim · CWE-787 | Kritik9,8 | KEV | %71,7 | 14 Ara 2010 |
81Hemen | CVE-2019-16928Silahlaştırılmış | Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846.exim · exim · CWE-787 | Kritik9,8 | KEV | %41,6 | 27 Eyl 2019 |
66Bu hafta | CVE-2010-4345Silahlaştırılmış | Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate confiexim · exim · CWE-77 | Yüksek7,8 | KEV | %18,0 | 14 Ara 2010 |
62Bu hafta | CVE-2025-26794Kavram kanıtı | Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.exim · exim · CWE-89 | Kritik9,8 | — | %77,6 | 21 Şub 2025 |
56Planlayın | CVE-2020-28018Kavram kanıtı | Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.exim · exim · CWE-416 | Kritik9,8 | — | %56,8 | 6 May 2021 |
53Planlayın | CVE-2017-16943Kavram kanıtı | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a exim · exim · CWE-416 | Kritik9,8 | — | %46,7 | 25 Kas 2017 |
50Planlayın | CVE-2020-28017İstismar yok | Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipientsexim · exim · CWE-190 | Kritik9,8 | — | %36,9 | 6 May 2021 |
50Planlayın | CVE-2019-15846Kavram kanıtı | Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.exim · exim | Kritik9,8 | — | %35,7 | 6 Eyl 2019 |
49Planlayın | CVE-2017-16944Kavram kanıtı | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinitexim · exim · CWE-835 | Yüksek7,5 | — | %63,3 | 25 Kas 2017 |
49Planlayın | CVE-2023-42118İstismar yok | Exim libspf2 Integer Underflow Remote Code Execution Vulnerabilityexim · exim · CWE-191 | Yüksek8,8 | — | %47,5 | 2 May 2024 |
48Planlayın | CVE-2020-28019İstismar yok | Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.exim · exim · CWE-665 | Yüksek7,5 | — | %61,7 | 6 May 2021 |
43Planlayın | CVE-2023-42115Kavram kanıtı | Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerabilityexim · exim · CWE-787 | Kritik9,8 | — | %11,7 | 2 May 2024 |
42Planlayın | CVE-2020-28026İstismar yok | Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notiexim · exim | Kritik9,8 | — | %9,3 | 6 May 2021 |
42Planlayın | CVE-2019-13917İstismar yok | Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansionexim · exim · CWE-19 | Kritik9,8 | — | %8,6 | 25 Tem 2019 |
41Planlayın | CVE-2020-28020İstismar yok | Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by levexim · exim · CWE-190 | Kritik9,8 | — | %7,9 | 6 May 2021 |
41Planlayın | CVE-2023-42117İstismar yok | Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerabilityexim · exim · CWE-138 | Kritik9,8 | — | %6,8 | 2 May 2024 |
40Planlayın | CVE-2020-28024İstismar yok | Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtpexim · exim · CWE-787 | Kritik9,8 | — | %4,2 | 6 May 2021 |
40Planlayın | CVE-2022-37452İstismar yok | Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.exim · exim · CWE-787 | Kritik9,8 | — | %3,8 | 7 Ağu 2022 |
40Planlayın | CVE-2023-42116İstismar yok | Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerabilityexim · exim · CWE-121 | Kritik9,8 | — | %3,8 | 2 May 2024 |
40Planlayın | CVE-2020-28022Kavram kanıtı | Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer.exim · exim · CWE-787 | Kritik9,8 | — | %3,0 | 6 May 2021 |
39İzleyin | CVE-2026-45185Kavram kanıtı | Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path.exim · exim · CWE-416 | Kritik9,8 | — | %0,9 | 12 May 2026 |
39İzleyin | CVE-2022-3620İstismar yok | Exim DMARC dmarc.c dmarc_dns_lookup use after freeexim · exim · CWE-119 | Kritik9,8 | — | %0,8 | 20 Eki 2022 |
39İzleyin | CVE-2026-40685İstismar yok | In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in exim · exim · CWE-684 | Kritik9,8 | — | %0,6 | 30 Nis 2026 |
- CVE-2019-1014999Hemen
A flaw was found in Exim versions 4.87 to 4.91 (inclusive).
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100exim · exim5 Haz 2019
- CVE-2018-678994Hemen
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %82exim · exim8 Şub 2018
- CVE-2010-434491Hemen
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %72exim · exim14 Ara 2010
- CVE-2019-1692881Hemen
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %42exim · exim27 Eyl 2019
- CVE-2010-434566Bu hafta
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate confi
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %18exim · exim14 Ara 2010
- CVE-2025-2679462Bu hafta
Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.
KritikCVSS 9,8Kavram kanıtıEPSS %78exim · exim21 Şub 2025
- CVE-2020-2801856Planlayın
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.
KritikCVSS 9,8Kavram kanıtıEPSS %57exim · exim6 May 2021
- CVE-2017-1694353Planlayın
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a
KritikCVSS 9,8Kavram kanıtıEPSS %47exim · exim25 Kas 2017
- CVE-2020-2801750Planlayın
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients
KritikCVSS 9,8İstismar yokEPSS %37exim · exim6 May 2021
- CVE-2019-1584650Planlayın
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
KritikCVSS 9,8Kavram kanıtıEPSS %36exim · exim6 Eyl 2019
- CVE-2017-1694449Planlayın
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinit
YüksekCVSS 7,5Kavram kanıtıEPSS %63exim · exim25 Kas 2017
- CVE-2023-4211849Planlayın
Exim libspf2 Integer Underflow Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %48exim · exim2 May 2024
- CVE-2020-2801948Planlayın
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.
YüksekCVSS 7,5İstismar yokEPSS %62exim · exim6 May 2021
- CVE-2023-4211543Planlayın
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %12exim · exim2 May 2024
- CVE-2020-2802642Planlayın
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Noti
KritikCVSS 9,8İstismar yokEPSS %9exim · exim6 May 2021
- CVE-2019-1391742Planlayın
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion
KritikCVSS 9,8İstismar yokEPSS %9exim · exim25 Tem 2019
- CVE-2020-2802041Planlayın
Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by lev
KritikCVSS 9,8İstismar yokEPSS %8exim · exim6 May 2021
- CVE-2023-4211741Planlayın
Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %7exim · exim2 May 2024
- CVE-2020-2802440Planlayın
Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp
KritikCVSS 9,8İstismar yokEPSS %4exim · exim6 May 2021
- CVE-2022-3745240Planlayın
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
KritikCVSS 9,8İstismar yokEPSS %4exim · exim7 Ağu 2022
- CVE-2023-4211640Planlayın
Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %4exim · exim2 May 2024
- CVE-2020-2802240Planlayın
Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer.
KritikCVSS 9,8Kavram kanıtıEPSS %3exim · exim6 May 2021
- CVE-2026-4518539İzleyin
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path.
KritikCVSS 9,8Kavram kanıtıEPSS %1exim · exim12 May 2026
- CVE-2022-362039İzleyin
Exim DMARC dmarc.c dmarc_dns_lookup use after free
KritikCVSS 9,8İstismar yokEPSS %1exim · exim20 Eki 2022
- CVE-2026-4068539İzleyin
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in
KritikCVSS 9,8İstismar yokEPSS %1exim · exim30 Nis 2026