Search CVE reports


Toggle filters

41 – 50 of 64 results


CVE-2019-13917

Medium priority
Fixed

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

1 affected package

exim4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Fixed
Show less packages

CVE-2019-10149

Medium priority
Fixed

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

1 affected package

exim4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Fixed
Show less packages

CVE-2018-6789

Medium priority
Fixed

An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.

1 affected package

exim4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4
Show less packages

CVE-2017-16944

Medium priority
Fixed

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for...

1 affected package

exim4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4
Show less packages

CVE-2017-16943

High priority
Fixed

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

1 affected package

exim4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4
Show less packages

CVE-2017-1000369

Medium priority
Fixed

Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and...

1 affected package

exim4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4
Show less packages

CVE-2016-9963

Medium priority
Fixed

Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.

1 affected package

exim4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4
Show less packages

CVE-2016-1531

Medium priority
Fixed

Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.

1 affected package

exim4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4
Show less packages

CVE-2014-2972

Low priority

Some fixes available 2 of 3

expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.

1 affected package

exim4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4
Show less packages

CVE-2014-2957

Negligible priority
Ignored

The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.

1 affected package

exim4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4
Show less packages