Vulnerabilities > Exim > Exim > 4.82

DATE CVE VULNERABILITY TITLE RISK
2021-05-06 CVE-2020-28026 Unspecified vulnerability in Exim
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN).
network
exim
critical
9.3
2021-05-06 CVE-2021-27216 Improper Privilege Management vulnerability in Exim
Exim 4 before 4.94.2 has Execution with Unnecessary Privileges.
local
exim CWE-269
6.3
2020-05-11 CVE-2020-12783 Out-of-bounds Read vulnerability in multiple products
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.
network
low complexity
exim fedoraproject debian canonical CWE-125
7.5
2020-04-02 CVE-2020-8015 Link Following vulnerability in Exim
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root.
local
low complexity
exim CWE-59
7.2
2019-09-06 CVE-2019-15846 Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
network
low complexity
exim debian
critical
9.8
2018-02-08 CVE-2018-6789 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.
network
low complexity
exim debian canonical CWE-119
7.5
2017-06-19 CVE-2017-1000369 Improper Resource Shutdown or Release vulnerability in multiple products
Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution.
local
low complexity
exim debian CWE-404
2.1
2017-02-01 CVE-2016-9963 Key Management Errors vulnerability in multiple products
Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
network
high complexity
exim canonical debian CWE-320
2.6
2016-04-07 CVE-2016-1531 Permissions, Privileges, and Access Controls vulnerability in Exim
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
local
exim CWE-264
6.9
2014-09-04 CVE-2014-2972 Numeric Errors vulnerability in Exim
expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.
local
low complexity
exim CWE-189
4.6