CVE Tracker
Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.
Showing 5 of 5 CVEs matching "Exim" · HIGH · CISA KEV
Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.
Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.
Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.