Vulnerabilities > Exim > Exim > 3.34

DATE CVE VULNERABILITY TITLE RISK
2023-12-24 CVE-2023-51766 Insufficient Verification of Data Authenticity vulnerability in multiple products
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations.
network
low complexity
exim fedoraproject debian CWE-345
5.3
2022-10-17 CVE-2022-3559 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A vulnerability was found in Exim and classified as problematic.
network
low complexity
exim fedoraproject CWE-119
7.5
2022-08-07 CVE-2022-37452 Out-of-bounds Write vulnerability in multiple products
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
network
low complexity
exim debian CWE-787
critical
9.8
2022-08-06 CVE-2022-37451 Release of Invalid Pointer or Reference vulnerability in multiple products
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
network
low complexity
exim fedoraproject CWE-763
7.5
2021-08-10 CVE-2021-38371 Injection vulnerability in Exim
The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.
network
low complexity
exim CWE-74
7.5
2021-05-06 CVE-2020-28017 Integer Overflow or Wraparound vulnerability in Exim
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients.
network
low complexity
exim CWE-190
critical
9.8
2021-05-06 CVE-2021-27216 Race Condition vulnerability in Exim
Exim 4 before 4.94.2 has Execution with Unnecessary Privileges.
local
high complexity
exim CWE-362
6.3
2020-05-11 CVE-2020-12783 Out-of-bounds Read vulnerability in multiple products
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.
network
low complexity
exim fedoraproject debian canonical CWE-125
7.5
2020-04-02 CVE-2020-8015 Unspecified vulnerability in Exim
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root.
local
low complexity
exim
7.8
2019-09-06 CVE-2019-15846 Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
network
low complexity
exim debian
critical
9.8