Skip to content
Noroxi

Exim records

71 published records for vendor exim.

Researcher profile

Entered KEV
5 · 7%
Weaponized
6 · 8.5%
Pre-auth RCE
18
With a fix record
100%
Median publish → KEV
1364 days

All records

71 records
  • A flaw was found in Exim versions 4.87 to 4.91 (inclusive).

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    exim · eximJun 5, 2019

  • An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.

    CriticalCVSS 9.8KEVWeaponizedEPSS 82%

    exim · eximFeb 8, 2018

  • Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code

    CriticalCVSS 9.8KEVWeaponizedEPSS 72%

    exim · eximDec 14, 2010

  • Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846.

    CriticalCVSS 9.8KEVWeaponizedEPSS 42%

    exim · eximSep 27, 2019

  • CVE-2010-4345
    66This week

    Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate confi

    HighCVSS 7.8KEVWeaponizedEPSS 18%

    exim · eximDec 14, 2010

  • CVE-2025-26794
    62This week

    Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.

    CriticalCVSS 9.8Proof of conceptEPSS 77%

    exim · eximFeb 21, 2025

  • Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.

    CriticalCVSS 9.8Proof of conceptEPSS 57%

    exim · eximMay 6, 2021

  • The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a

    CriticalCVSS 9.8Proof of conceptEPSS 47%

    exim · eximNov 25, 2017

  • Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients

    CriticalCVSS 9.8No exploitEPSS 37%

    exim · eximMay 6, 2021

  • Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.

    CriticalCVSS 9.8Proof of conceptEPSS 36%

    exim · eximSep 6, 2019

  • The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinit

    HighCVSS 7.5Proof of conceptEPSS 63%

    exim · eximNov 25, 2017

  • Exim libspf2 Integer Underflow Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 48%

    exim · eximMay 2, 2024

  • Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.

    HighCVSS 7.5No exploitEPSS 62%

    exim · eximMay 6, 2021

  • Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 11%

    exim · eximMay 2, 2024

  • Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Noti

    CriticalCVSS 9.8No exploitEPSS 9%

    exim · eximMay 6, 2021

  • Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion

    CriticalCVSS 9.8No exploitEPSS 9%

    exim · eximJul 25, 2019

  • Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by lev

    CriticalCVSS 9.8No exploitEPSS 8%

    exim · eximMay 6, 2021

  • Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 7%

    exim · eximMay 2, 2024

  • Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp

    CriticalCVSS 9.8No exploitEPSS 4%

    exim · eximMay 6, 2021

  • Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

    CriticalCVSS 9.8No exploitEPSS 4%

    exim · eximAug 7, 2022

  • Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 4%

    exim · eximMay 2, 2024

  • Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    exim · eximMay 6, 2021

  • Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path.

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    exim · eximMay 12, 2026

  • CVE-2022-3620
    39Monitor

    Exim DMARC dmarc.c dmarc_dns_lookup use after free

    CriticalCVSS 9.8No exploitEPSS 1%

    exim · eximOct 20, 2022

  • In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in

    CriticalCVSS 9.8No exploitEPSS 1%

    exim · eximApr 30, 2026