Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-66140 Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related … Exim 4.99.5+ Fix from $1,9502026-07-24 HIGH 7.8 CVE-2026-66141 Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled. Exim 4.99.5+ Fix from $1,9502026-07-24 MEDIUM 5.3 CVE-2026-48840 Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values … Exim 4.99.4+ Fix from $1,6002026-05-30 CRITICAL 9.8 CVE-2026-45185 Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a c… Exim 4.99.3+ Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-40685 In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrus… Exim 4.99.2+ Fix from $2,3002026-04-30 CRITICAL 9.1 CVE-2026-40687 In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes … Exim 4.99.2+ Fix from $2,3002026-04-30 HIGH 7.5 CVE-2026-40684 In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PT… Exim 4.99.2+ Fix from $1,9502026-04-30 MEDIUM 5.3 CVE-2026-40686 In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-… Exim 4.99.2+ Fix from $1,6002026-04-30 CRITICAL 9.8 CVE-2025-67896 Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast … Exim 4.99.1+ Fix from $2,3002025-12-14 HIGH 7.8 CVE-2025-30232 A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges. Exim after 4.98.1 Fix from $1,9502025-03-28 CRITICAL 9.8 CVE-2025-26794EPSS 77% Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update … Exim 4.98.1+ Fix from $2,3002025-02-21 MEDIUM 5.4 CVE-2024-39929EPSS 41% Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protecti… Exim after 4.97.1 Fix from $1,6002024-07-04 CRITICAL 9.8 CVE-2023-42115EPSS 10% Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected i… Exim 4.96.1+ Fix from $2,3002024-05-03 CRITICAL 9.8 CVE-2023-42116 Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary … Exim 4.96.1+ Fix from $2,3002024-05-03 CRITICAL 9.8 CVE-2023-42117EPSS 6% Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… Exim 4.96.2+ Fix from $2,3002024-05-03 MEDIUM 5.3 CVE-2023-42114EPSS 28% Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive informa… Exim 4.96.1+ Fix from $1,6002024-05-03 HIGH 7.5 CVE-2021-38371 The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending. Exim after 4.94.2 Fix from $1,9502021-08-10 MEDIUM 6.3 CVE-2021-27216 Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary fil… Exim 4.94.2+ Fix from $1,6002021-05-06 CRITICAL 9.8 CVE-2020-28017EPSS 37% Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: r… Exim 4.94.1+ Fix from $2,3002021-05-06 CRITICAL 9.8 CVE-2020-28018EPSS 57% Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL. Exim 4.94.2+ Fix from $2,3002021-05-06 CRITICAL 9.8 CVE-2020-28020EPSS 8% Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by leveraging t… Exim 4.92+ Fix from $2,3002021-05-06 CRITICAL 9.8 CVE-2020-28022 Exim 4 before 4.94.2 has Improper Restriction of Write Operations within the Bounds of a Memory Buffer. This occurs when processing name=value pairs … Exim 4.94.2+ Fix from $2,3002021-05-06 CRITICAL 9.8 CVE-2020-28024 Exim 4 before 4.94.2 allows Buffer Underwrite that may result in unauthenticated remote attackers executing arbitrary commands, because smtp_ungetc w… Exim 4.94.2+ Fix from $2,3002021-05-06 CRITICAL 9.8 CVE-2020-28026EPSS 9% Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification … Exim 4.94.2+ Fix from $2,3002021-05-06 HIGH 8.8 CVE-2020-28021 Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. An authenticated remote SMTP client can insert newline characters into a spool f… Exim 4.94.2+ Fix from $1,9502021-05-06 HIGH 7.8 CVE-2020-28007 Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a s… Exim 4.94.2+ Fix from $1,9502021-05-06 HIGH 7.8 CVE-2020-28008 Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the spool directory (owned by a non-root user), a… Exim 4.94.2+ Fix from $1,9502021-05-06 HIGH 7.8 CVE-2020-28009 Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads that are accompanied by unbounded increas… Exim 4.94.2+ Fix from $1,9502021-05-06 HIGH 7.8 CVE-2020-28010 Exim 4 before 4.94.2 allows Out-of-bounds Write because the main function, while setuid root, copies the current working directory pathname into a bu… Exim 4.94.2+ Fix from $1,9502021-05-06 HIGH 7.8 CVE-2020-28011 Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queue_run via two sender options: -R and -S. This may cause privilege escalation from exim … Exim 4.94.2+ Fix from $1,9502021-05-06