CVE-2010-4344
CRITICAL KEVExim < 4.70 - Out-of-Bounds Write
Title source: ruleDescription
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by kingcope · perlremotelinux
https://www.exploit-db.com/exploits/15725
References (34)
... and 14 more
Scores
CVSS v3
9.8
EPSS
0.6146
EPSS Percentile
98.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2022-03-25
VulnCheck KEV
2010-12-10
InTheWild.io
2022-03-25
ENISA EUVD
EUVD-2010-4313
Classification
CWE
CWE-787
Status
draft
Affected Products (8)
exim/exim
< 4.70
opensuse/opensuse
opensuse/opensuse
opensuse/opensuse
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
Timeline
Published
Dec 14, 2010
KEV Added
Mar 25, 2022
Tracked Since
Feb 18, 2026