Exim records
71 published records for vendor exim.
Researcher profile
- Entered KEV
- 5 · 7%
- Weaponized
- 6 · 8.5%
- Pre-auth RCE
- 18
- With a fix record
- 100%
- Median publish → KEV
- 1364 days
Recurring classes
- CWE-787 Out-of-bounds Write11
- CWE-125 Out-of-bounds Read6
- CWE-416 Use After Free5
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')3
- CWE-20 Improper Input Validation3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
The weakness classes this vendor ships most often: where to look.
CWEAll records
71 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2019-10149Weaponized | A flaw was found in Exim versions 4.87 to 4.91 (inclusive).exim · exim · CWE-78 | Critical9.8 | KEV | 100.0% | Jun 5, 2019 |
94Now | CVE-2018-6789Weaponized | An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.exim · exim · CWE-120 | Critical9.8 | KEV | 82.1% | Feb 8, 2018 |
91Now | CVE-2010-4344Weaponized | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code exim · exim · CWE-787 | Critical9.8 | KEV | 71.7% | Dec 14, 2010 |
81Now | CVE-2019-16928Weaponized | Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846.exim · exim · CWE-787 | Critical9.8 | KEV | 41.6% | Sep 27, 2019 |
66This week | CVE-2010-4345Weaponized | Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate confiexim · exim · CWE-77 | High7.8 | KEV | 18.0% | Dec 14, 2010 |
62This week | CVE-2025-26794Proof of concept | Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.exim · exim · CWE-89 | Critical9.8 | — | 77.2% | Feb 21, 2025 |
56Plan | CVE-2020-28018Proof of concept | Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.exim · exim · CWE-416 | Critical9.8 | — | 56.8% | May 6, 2021 |
53Plan | CVE-2017-16943Proof of concept | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a exim · exim · CWE-416 | Critical9.8 | — | 46.7% | Nov 25, 2017 |
50Plan | CVE-2020-28017No exploit | Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipientsexim · exim · CWE-190 | Critical9.8 | — | 36.9% | May 6, 2021 |
50Plan | CVE-2019-15846Proof of concept | Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.exim · exim | Critical9.8 | — | 35.7% | Sep 6, 2019 |
49Plan | CVE-2017-16944Proof of concept | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinitexim · exim · CWE-835 | High7.5 | — | 63.3% | Nov 25, 2017 |
49Plan | CVE-2023-42118No exploit | Exim libspf2 Integer Underflow Remote Code Execution Vulnerabilityexim · exim · CWE-191 | High8.8 | — | 48.1% | May 2, 2024 |
48Plan | CVE-2020-28019No exploit | Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.exim · exim · CWE-665 | High7.5 | — | 61.7% | May 6, 2021 |
42Plan | CVE-2023-42115Proof of concept | Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerabilityexim · exim · CWE-787 | Critical9.8 | — | 11.3% | May 2, 2024 |
42Plan | CVE-2020-28026No exploit | Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notiexim · exim | Critical9.8 | — | 9.3% | May 6, 2021 |
42Plan | CVE-2019-13917No exploit | Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansionexim · exim · CWE-19 | Critical9.8 | — | 8.6% | Jul 25, 2019 |
41Plan | CVE-2020-28020No exploit | Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by levexim · exim · CWE-190 | Critical9.8 | — | 7.9% | May 6, 2021 |
41Plan | CVE-2023-42117No exploit | Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerabilityexim · exim · CWE-138 | Critical9.8 | — | 6.5% | May 2, 2024 |
40Plan | CVE-2020-28024No exploit | Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtpexim · exim · CWE-787 | Critical9.8 | — | 4.2% | May 6, 2021 |
40Plan | CVE-2022-37452No exploit | Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.exim · exim · CWE-787 | Critical9.8 | — | 3.8% | Aug 7, 2022 |
40Plan | CVE-2023-42116No exploit | Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerabilityexim · exim · CWE-121 | Critical9.8 | — | 3.6% | May 2, 2024 |
40Plan | CVE-2020-28022Proof of concept | Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer.exim · exim · CWE-787 | Critical9.8 | — | 3.0% | May 6, 2021 |
39Monitor | CVE-2026-45185Proof of concept | Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path.exim · exim · CWE-416 | Critical9.8 | — | 0.9% | May 12, 2026 |
39Monitor | CVE-2022-3620No exploit | Exim DMARC dmarc.c dmarc_dns_lookup use after freeexim · exim · CWE-119 | Critical9.8 | — | 0.8% | Oct 20, 2022 |
39Monitor | CVE-2026-40685No exploit | In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in exim · exim · CWE-684 | Critical9.8 | — | 0.6% | Apr 30, 2026 |
- CVE-2019-1014999Now
A flaw was found in Exim versions 4.87 to 4.91 (inclusive).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%exim · eximJun 5, 2019
- CVE-2018-678994Now
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.
CriticalCVSS 9.8KEVWeaponizedEPSS 82%exim · eximFeb 8, 2018
- CVE-2010-434491Now
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code
CriticalCVSS 9.8KEVWeaponizedEPSS 72%exim · eximDec 14, 2010
- CVE-2019-1692881Now
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846.
CriticalCVSS 9.8KEVWeaponizedEPSS 42%exim · eximSep 27, 2019
- CVE-2010-434566This week
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate confi
HighCVSS 7.8KEVWeaponizedEPSS 18%exim · eximDec 14, 2010
- CVE-2025-2679462This week
Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.
CriticalCVSS 9.8Proof of conceptEPSS 77%exim · eximFeb 21, 2025
- CVE-2020-2801856Plan
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.
CriticalCVSS 9.8Proof of conceptEPSS 57%exim · eximMay 6, 2021
- CVE-2017-1694353Plan
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a
CriticalCVSS 9.8Proof of conceptEPSS 47%exim · eximNov 25, 2017
- CVE-2020-2801750Plan
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients
CriticalCVSS 9.8No exploitEPSS 37%exim · eximMay 6, 2021
- CVE-2019-1584650Plan
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
CriticalCVSS 9.8Proof of conceptEPSS 36%exim · eximSep 6, 2019
- CVE-2017-1694449Plan
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinit
HighCVSS 7.5Proof of conceptEPSS 63%exim · eximNov 25, 2017
- CVE-2023-4211849Plan
Exim libspf2 Integer Underflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 48%exim · eximMay 2, 2024
- CVE-2020-2801948Plan
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.
HighCVSS 7.5No exploitEPSS 62%exim · eximMay 6, 2021
- CVE-2023-4211542Plan
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 11%exim · eximMay 2, 2024
- CVE-2020-2802642Plan
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Noti
CriticalCVSS 9.8No exploitEPSS 9%exim · eximMay 6, 2021
- CVE-2019-1391742Plan
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion
CriticalCVSS 9.8No exploitEPSS 9%exim · eximJul 25, 2019
- CVE-2020-2802041Plan
Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by lev
CriticalCVSS 9.8No exploitEPSS 8%exim · eximMay 6, 2021
- CVE-2023-4211741Plan
Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 7%exim · eximMay 2, 2024
- CVE-2020-2802440Plan
Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp
CriticalCVSS 9.8No exploitEPSS 4%exim · eximMay 6, 2021
- CVE-2022-3745240Plan
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
CriticalCVSS 9.8No exploitEPSS 4%exim · eximAug 7, 2022
- CVE-2023-4211640Plan
Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 4%exim · eximMay 2, 2024
- CVE-2020-2802240Plan
Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer.
CriticalCVSS 9.8Proof of conceptEPSS 3%exim · eximMay 6, 2021
- CVE-2026-4518539Monitor
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path.
CriticalCVSS 9.8Proof of conceptEPSS 1%exim · eximMay 12, 2026
- CVE-2022-362039Monitor
Exim DMARC dmarc.c dmarc_dns_lookup use after free
CriticalCVSS 9.8No exploitEPSS 1%exim · eximOct 20, 2022
- CVE-2026-4068539Monitor
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in
CriticalCVSS 9.8No exploitEPSS 1%exim · eximApr 30, 2026