Vulnerabilities
Vulnerable Software
Exim:  >> Exim  >> 4.90  Security Vulnerabilities
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).
CVSS Score
9.8
EPSS Score
0.199
Published
2019-07-25
CVE-2019-10149
Known exploited
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
CVSS Score
9.0
EPSS Score
0.939
Published
2019-06-05
CVE-2018-6789
Known exploited
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
CVSS Score
9.8
EPSS Score
0.864
Published
2018-02-08


Contact Us

Shodan ® - All rights reserved