CVE-2010-4344
CRITICAL KEVExim < 4.70 - Out-of-Bounds Write
Title source: ruleDescription
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by kingcope · perlremotelinux
https://www.exploit-db.com/exploits/15725
References (34)
... and 14 more
Scores
CVSS v3
9.8
EPSS
0.5306
EPSS Percentile
98.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-03-25
VulnCheck KEV
2010-12-10
InTheWild.io
2022-03-25
ENISA EUVD
EUVD-2010-4313
CWE
CWE-787
Status
published
Products (8)
canonical/ubuntu_linux
6.06
canonical/ubuntu_linux
8.04
canonical/ubuntu_linux
9.10
debian/debian_linux
5.0
exim/exim
< 4.70
opensuse/opensuse
11.1
opensuse/opensuse
11.2
opensuse/opensuse
11.3
Published
Dec 14, 2010
KEV Added
Mar 25, 2022
Tracked Since
Feb 18, 2026