İçeriğe atla
Noroxi

Exim kayıtları

exim üreticisine ait 71 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
5 · %7
Silahlaştırılmış
6 · %8,5
Pre-auth RCE
18
Düzeltme kaydı olan
%100
Yayından KEV’e ortanca
1364 gün

Tüm kayıtlar

71 kayıt
  • A flaw was found in Exim versions 4.87 to 4.91 (inclusive).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    exim · exim5 Haz 2019

  • An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %82

    exim · exim8 Şub 2018

  • Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %72

    exim · exim14 Ara 2010

  • Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %42

    exim · exim27 Eyl 2019

  • CVE-2010-4345
    66Bu hafta

    Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate confi

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %18

    exim · exim14 Ara 2010

  • CVE-2025-26794
    62Bu hafta

    Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.

    KritikCVSS 9,8Kavram kanıtıEPSS %78

    exim · exim21 Şub 2025

  • CVE-2020-28018
    56Planlayın

    Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.

    KritikCVSS 9,8Kavram kanıtıEPSS %57

    exim · exim6 May 2021

  • CVE-2017-16943
    53Planlayın

    The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a

    KritikCVSS 9,8Kavram kanıtıEPSS %47

    exim · exim25 Kas 2017

  • CVE-2020-28017
    50Planlayın

    Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients

    KritikCVSS 9,8İstismar yokEPSS %37

    exim · exim6 May 2021

  • CVE-2019-15846
    50Planlayın

    Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.

    KritikCVSS 9,8Kavram kanıtıEPSS %36

    exim · exim6 Eyl 2019

  • CVE-2017-16944
    49Planlayın

    The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinit

    YüksekCVSS 7,5Kavram kanıtıEPSS %63

    exim · exim25 Kas 2017

  • CVE-2023-42118
    49Planlayın

    Exim libspf2 Integer Underflow Remote Code Execution Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %48

    exim · exim2 May 2024

  • CVE-2020-28019
    48Planlayın

    Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.

    YüksekCVSS 7,5İstismar yokEPSS %62

    exim · exim6 May 2021

  • CVE-2023-42115
    43Planlayın

    Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability

    KritikCVSS 9,8Kavram kanıtıEPSS %12

    exim · exim2 May 2024

  • CVE-2020-28026
    42Planlayın

    Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Noti

    KritikCVSS 9,8İstismar yokEPSS %9

    exim · exim6 May 2021

  • CVE-2019-13917
    42Planlayın

    Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion

    KritikCVSS 9,8İstismar yokEPSS %9

    exim · exim25 Tem 2019

  • CVE-2020-28020
    41Planlayın

    Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by lev

    KritikCVSS 9,8İstismar yokEPSS %8

    exim · exim6 May 2021

  • CVE-2023-42117
    41Planlayın

    Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %7

    exim · exim2 May 2024

  • CVE-2020-28024
    40Planlayın

    Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp

    KritikCVSS 9,8İstismar yokEPSS %4

    exim · exim6 May 2021

  • CVE-2022-37452
    40Planlayın

    Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

    KritikCVSS 9,8İstismar yokEPSS %4

    exim · exim7 Ağu 2022

  • CVE-2023-42116
    40Planlayın

    Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %4

    exim · exim2 May 2024

  • CVE-2020-28022
    40Planlayın

    Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer.

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    exim · exim6 May 2021

  • CVE-2026-45185
    39İzleyin

    Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path.

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    exim · exim12 May 2026

  • CVE-2022-3620
    39İzleyin

    Exim DMARC dmarc.c dmarc_dns_lookup use after free

    KritikCVSS 9,8İstismar yokEPSS %1

    exim · exim20 Eki 2022

  • CVE-2026-40685
    39İzleyin

    In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in

    KritikCVSS 9,8İstismar yokEPSS %1

    exim · exim30 Nis 2026