Записи Exim
71 опубликованных записей вендора exim.
Профиль для исследователя
- Попали в KEV
- 5 · 7 %
- С эксплойтом
- 6 · 8,5 %
- Pre-auth RCE
- 18
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- 1364 дн.
Повторяющиеся классы
- CWE-787 Out-of-bounds Write11
- CWE-125 Out-of-bounds Read6
- CWE-416 Use After Free5
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')3
- CWE-20 Improper Input Validation3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
71 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2019-10149Готовый эксплойт | A flaw was found in Exim versions 4.87 to 4.91 (inclusive).exim · exim · CWE-78 | Критическая9,8 | KEV | 100,0 % | 5 июн. 2019 г. |
94Срочно | CVE-2018-6789Готовый эксплойт | An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.exim · exim · CWE-120 | Критическая9,8 | KEV | 82,1 % | 8 февр. 2018 г. |
91Срочно | CVE-2010-4344Готовый эксплойт | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code exim · exim · CWE-787 | Критическая9,8 | KEV | 71,7 % | 14 дек. 2010 г. |
81Срочно | CVE-2019-16928Готовый эксплойт | Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846.exim · exim · CWE-787 | Критическая9,8 | KEV | 41,6 % | 27 сент. 2019 г. |
66На этой неделе | CVE-2010-4345Готовый эксплойт | Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate confiexim · exim · CWE-77 | Высокая7,8 | KEV | 18,0 % | 14 дек. 2010 г. |
62На этой неделе | CVE-2025-26794Proof of concept | Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.exim · exim · CWE-89 | Критическая9,8 | — | 77,6 % | 21 февр. 2025 г. |
56В плане | CVE-2020-28018Proof of concept | Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.exim · exim · CWE-416 | Критическая9,8 | — | 56,8 % | 6 мая 2021 г. |
53В плане | CVE-2017-16943Proof of concept | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a exim · exim · CWE-416 | Критическая9,8 | — | 46,7 % | 25 нояб. 2017 г. |
50В плане | CVE-2020-28017Эксплойта нет | Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipientsexim · exim · CWE-190 | Критическая9,8 | — | 36,9 % | 6 мая 2021 г. |
50В плане | CVE-2019-15846Proof of concept | Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.exim · exim | Критическая9,8 | — | 35,7 % | 6 сент. 2019 г. |
49В плане | CVE-2017-16944Proof of concept | The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinitexim · exim · CWE-835 | Высокая7,5 | — | 63,3 % | 25 нояб. 2017 г. |
49В плане | CVE-2023-42118Эксплойта нет | Exim libspf2 Integer Underflow Remote Code Execution Vulnerabilityexim · exim · CWE-191 | Высокая8,8 | — | 47,5 % | 2 мая 2024 г. |
48В плане | CVE-2020-28019Эксплойта нет | Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.exim · exim · CWE-665 | Высокая7,5 | — | 61,7 % | 6 мая 2021 г. |
43В плане | CVE-2023-42115Proof of concept | Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerabilityexim · exim · CWE-787 | Критическая9,8 | — | 11,7 % | 2 мая 2024 г. |
42В плане | CVE-2020-28026Эксплойта нет | Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notiexim · exim | Критическая9,8 | — | 9,3 % | 6 мая 2021 г. |
42В плане | CVE-2019-13917Эксплойта нет | Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansionexim · exim · CWE-19 | Критическая9,8 | — | 8,6 % | 25 июл. 2019 г. |
41В плане | CVE-2020-28020Эксплойта нет | Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by levexim · exim · CWE-190 | Критическая9,8 | — | 7,9 % | 6 мая 2021 г. |
41В плане | CVE-2023-42117Эксплойта нет | Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerabilityexim · exim · CWE-138 | Критическая9,8 | — | 6,8 % | 2 мая 2024 г. |
40В плане | CVE-2020-28024Эксплойта нет | Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtpexim · exim · CWE-787 | Критическая9,8 | — | 4,2 % | 6 мая 2021 г. |
40В плане | CVE-2022-37452Эксплойта нет | Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.exim · exim · CWE-787 | Критическая9,8 | — | 3,8 % | 7 авг. 2022 г. |
40В плане | CVE-2023-42116Эксплойта нет | Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerabilityexim · exim · CWE-121 | Критическая9,8 | — | 3,8 % | 2 мая 2024 г. |
40В плане | CVE-2020-28022Proof of concept | Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer.exim · exim · CWE-787 | Критическая9,8 | — | 3,0 % | 6 мая 2021 г. |
39Наблюдать | CVE-2026-45185Proof of concept | Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path.exim · exim · CWE-416 | Критическая9,8 | — | 0,9 % | 12 мая 2026 г. |
39Наблюдать | CVE-2022-3620Эксплойта нет | Exim DMARC dmarc.c dmarc_dns_lookup use after freeexim · exim · CWE-119 | Критическая9,8 | — | 0,8 % | 20 окт. 2022 г. |
39Наблюдать | CVE-2026-40685Эксплойта нет | In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in exim · exim · CWE-684 | Критическая9,8 | — | 0,6 % | 30 апр. 2026 г. |
- CVE-2019-1014999Срочно
A flaw was found in Exim versions 4.87 to 4.91 (inclusive).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %exim · exim5 июн. 2019 г.
- CVE-2018-678994Срочно
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 82 %exim · exim8 февр. 2018 г.
- CVE-2010-434491Срочно
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 72 %exim · exim14 дек. 2010 г.
- CVE-2019-1692881Срочно
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 42 %exim · exim27 сент. 2019 г.
- CVE-2010-434566На этой неделе
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate confi
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 18 %exim · exim14 дек. 2010 г.
- CVE-2025-2679462На этой неделе
Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.
КритическаяCVSS 9,8Proof of conceptEPSS 78 %exim · exim21 февр. 2025 г.
- CVE-2020-2801856В плане
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.
КритическаяCVSS 9,8Proof of conceptEPSS 57 %exim · exim6 мая 2021 г.
- CVE-2017-1694353В плане
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a
КритическаяCVSS 9,8Proof of conceptEPSS 47 %exim · exim25 нояб. 2017 г.
- CVE-2020-2801750В плане
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients
КритическаяCVSS 9,8Эксплойта нетEPSS 37 %exim · exim6 мая 2021 г.
- CVE-2019-1584650В плане
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
КритическаяCVSS 9,8Proof of conceptEPSS 36 %exim · exim6 сент. 2019 г.
- CVE-2017-1694449В плане
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinit
ВысокаяCVSS 7,5Proof of conceptEPSS 63 %exim · exim25 нояб. 2017 г.
- CVE-2023-4211849В плане
Exim libspf2 Integer Underflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 48 %exim · exim2 мая 2024 г.
- CVE-2020-2801948В плане
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.
ВысокаяCVSS 7,5Эксплойта нетEPSS 62 %exim · exim6 мая 2021 г.
- CVE-2023-4211543В плане
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 12 %exim · exim2 мая 2024 г.
- CVE-2020-2802642В плане
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Noti
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %exim · exim6 мая 2021 г.
- CVE-2019-1391742В плане
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %exim · exim25 июл. 2019 г.
- CVE-2020-2802041В плане
Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by lev
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %exim · exim6 мая 2021 г.
- CVE-2023-4211741В плане
Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %exim · exim2 мая 2024 г.
- CVE-2020-2802440В плане
Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %exim · exim6 мая 2021 г.
- CVE-2022-3745240В плане
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %exim · exim7 авг. 2022 г.
- CVE-2023-4211640В плане
Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %exim · exim2 мая 2024 г.
- CVE-2020-2802240В плане
Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %exim · exim6 мая 2021 г.
- CVE-2026-4518539Наблюдать
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path.
КритическаяCVSS 9,8Proof of conceptEPSS 1 %exim · exim12 мая 2026 г.
- CVE-2022-362039Наблюдать
Exim DMARC dmarc.c dmarc_dns_lookup use after free
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %exim · exim20 окт. 2022 г.
- CVE-2026-4068539Наблюдать
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %exim · exim30 апр. 2026 г.