Showing 24 vulnerabilities on this page for Exim

Signals CISA KEV Ransomware Nuclei
Exim vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:Exim .forward File Privilege Escalation via Pipe Transport force_command

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

CWE-829Jul 24, 2026
CVSS7.4v3.1EPSS0.102%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Exim Directory Traversal via Queue Name Arguments

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

CWE-24Jul 24, 2026
CVSS8.4v3.1EPSS0.272%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Exim Proxy Configuration Uninitialized Stack Memory Disclosure

Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.

CWE-839May 30, 2026
CVSS5.3v3.1EPSS0.264%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Exim BDAT Body Parsing Use-After-Free in GnuTLS Configurations

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

CWE-416May 12, 2026
CVSS9.8v3.1EPSS1.23%PoCs4SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Exim DNS PTR Record Handling Denial of Service Vulnerability

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

CWE-684Apr 30, 2026
CVSS5.9v3.1EPSS0.362%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Exim SPA Authentication Driver Out-of-bounds Write and Information Disclosure

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

CWE-909Apr 30, 2026
CVSS4.8v3.1EPSS0.373%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Exim Out-of-Bounds Read in UTF-8 Operators

In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.

CWE-125Apr 30, 2026
CVSS3.7v3.1EPSS0.246%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Exim Out-of-Bounds Heap Write in JSON Lookup

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

CWE-684CWE-787Apr 30, 2026
CVSS6.5v3.1EPSS0.321%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

CWE-122Dec 14, 2025
CVSS7.0v3.1EPSS0.463%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.

CWE-416Mar 27, 2025
CVSS8.1v3.1EPSS0.521%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)

CWE-89Feb 21, 2025
CVSS7.5v3.1EPSS77.2%PoCs3SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

CWE-116Jul 4, 2024
CVSS5.4v3.1EPSS41.2%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability

Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can

CWE-125May 3, 2024
CVSS3.1v3.0EPSS1.61%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability

Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this

CWE-138May 3, 2024
CVSS9.8v3.1EPSS5.72%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability

Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage thi

CWE-121May 3, 2024
CVSS9.8v3.1EPSS3.16%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability

Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of a buffer. An attacker can leverage this vulnerability

CWE-787May 3, 2024
CVSS9.8v3.0EPSS9.96%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability

Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NTLM challenge requests. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage th

CWE-125May 3, 2024
CVSS5.3v3.1EPSS28.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim Out-of-bounds Write Vulnerability

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

CWE-120CWE-787Sep 27, 2019
CVSS9.8v3.1EPSS41.6%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim before 4.92.2 Trailing Backslash Remote Code Execution

Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.

Sep 6, 2019
CVSS9.8v3.0EPSS35.7%PoCs1SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Exim Mail Transfer Agent (MTA) Improper Input Validation

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

CWE-20CWE-78Jun 5, 2019
CVSS9.8v3.1EPSS>99.9%PoCs22SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim Buffer Overflow Vulnerability

An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.

CWE-119CWE-120Feb 8, 2018
CVSS9.8v3.1EPSS81.7%PoCs6SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Exim Exim Improper Restriction of Operations within the Bounds of a Memory Buffer

Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.

CWE-119Oct 31, 2012
CVSS6.8v2.0EPSS8.38%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim Privilege Escalation Vulnerability

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.

CWE-264CWE-77Dec 14, 2010
CVSS7.8v3.1EPSS18.1%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exim Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

CWE-119CWE-787Dec 14, 2010
CVSS9.8v3.1EPSS71.9%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX