Vulnerabilities
Vulnerable Software
Exim:  >> Exim  >> 4.98.2  Security Vulnerabilities
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
CVSS Score
7.5
EPSS Score
0.004
Published
2026-09-19
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
CVSS Score
4.0
EPSS Score
0.003
Published
2026-09-19
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
CVSS Score
7.0
EPSS Score
0.003
Published
2026-09-19
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
CVSS Score
3.7
EPSS Score
0.004
Published
2026-09-19
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
CVSS Score
8.4
EPSS Score
0.003
Published
2026-07-24
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
CVSS Score
7.4
EPSS Score
0.001
Published
2026-07-24
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
CVSS Score
5.3
EPSS Score
0.003
Published
2026-05-30
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
CVSS Score
9.8
EPSS Score
0.012
Published
2026-05-12
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
CVSS Score
5.9
EPSS Score
0.004
Published
2026-04-30
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-04-30


Contact Us

Shodan ® - All rights reserved