Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Exim HIGH 7.8
CVE-2020-28012

Exim 4 before 4.94.2 allows Exposure of File Descriptor to Unintended Control Sphere because rda_interpret uses a privileged pipe that lacks a close-…

Fix: 4.94.2+
Fix from $1,950 2021-05-06
Exim HIGH 7.8
CVE-2020-28013

Exim 4 before 4.94.2 allows Heap-based Buffer Overflow because it mishandles "-F '.('" on the command line, and thus may allow privilege escalation f…

Fix: 4.94.2+
Fix from $1,950 2021-05-06
Exim HIGH 7.8
CVE-2020-28015

Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processes because a recipient address…

Fix: 4.94.2+
Fix from $1,950 2021-05-06
Exim HIGH 7.8
CVE-2020-28016

Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parse_fix_phrase.

Fix: 4.94.2+
Fix from $1,950 2021-05-06
Exim HIGH 7.5
CVE-2020-28019EPSS 62%

Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of…

Fix: 4.94.2+
Fix from $1,950 2021-05-06
Exim HIGH 7.5
CVE-2020-28023

Exim 4 before 4.94.2 allows Out-of-bounds Read. smtp_setup_msg may disclose sensitive information from process memory to an unauthenticated SMTP clie…

Fix: 4.94.2+
Fix from $1,950 2021-05-06
Exim HIGH 7.5
CVE-2020-28025

Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between sig->bodyhash.len and b->bh.l…

Fix: 4.94.2+
Fix from $1,950 2021-05-06
Exim MEDIUM 6.1
CVE-2020-28014

Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. The -oP option is available to the exim user, and allows a denial of service becau…

Fix: 4.94.2+
Fix from $1,600 2021-05-06
Exim HIGH 7.8
CVE-2020-8015

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail…

Fix: 4.93.0.4-3.1+
Fix from $1,950 2020-04-02
Exim HIGH 7.0
CVE-2016-1531EPSS 6%

Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.

Fix: after 4.86
Fix from $1,950 2016-04-07
Exim MEDIUM 6.8
CVE-2014-2957EPSS 5%

The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code vi…

Fix: after 4.82
Fix from $1,600 2014-09-04
Exim MEDIUM 6.8
CVE-2012-5671EPSS 8%

Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_con…

Mitigation only
Fix from $1,600 2012-10-31
Exim HIGH 7.5
CVE-2011-1764

Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitra…

Fix: after 4.75
Fix from $1,950 2011-10-05
Exim HIGH 7.5
CVE-2011-1407

The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows…

Patch available
Fix from $1,950 2011-05-16
Exim MEDIUM 6.9
CVE-2011-0017

The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows loca…

Fix: after 4.72
Fix from $1,600 2011-02-02