Vulnerabilities
Vulnerable Software
Exim:  >> Exim  >> 4.99.3  Security Vulnerabilities
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
CVSS Score
7.5
EPSS Score
0.004
Published
2026-09-19
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
CVSS Score
4.0
EPSS Score
0.003
Published
2026-09-19
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
CVSS Score
7.0
EPSS Score
0.003
Published
2026-09-19
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
CVSS Score
3.7
EPSS Score
0.004
Published
2026-09-19
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
CVSS Score
8.4
EPSS Score
0.003
Published
2026-07-24
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
CVSS Score
7.4
EPSS Score
0.001
Published
2026-07-24
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
CVSS Score
5.3
EPSS Score
0.003
Published
2026-05-30


Contact Us

Shodan ® - All rights reserved