📦 Exim

by Exim

🔍 What is Exim?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-42115

CRITICAL CVSS 9.8 May 3, 2024

CVE-2023-42115 is a critical out-of-bounds write vulnerability in Exim's SMTP service that allows unauthenticated remote attackers to execute arbitrary code on vulnerable systems. This affects Exim in...

CVE-2023-42117

CRITICAL CVSS 9.8 May 3, 2024

This is a critical remote code execution vulnerability in Exim mail servers that allows unauthenticated attackers to execute arbitrary code by sending specially crafted data to the SMTP service. The v...

CVE-2020-28017

CRITICAL CVSS 9.8 May 6, 2021

CVE-2020-28017 is an integer overflow vulnerability in Exim mail transfer agent that can lead to buffer overflow when processing emails with an excessive number of recipients. This affects Exim server...

CVE-2020-28020

CRITICAL CVSS 9.8 May 6, 2021

CVE-2020-28020 is an integer overflow vulnerability in Exim mail transfer agent that leads to buffer overflow, allowing unauthenticated remote attackers to execute arbitrary code by exploiting header ...

CVE-2020-28022

CRITICAL CVSS 9.8 May 6, 2021

CVE-2020-28022 is a critical heap-based buffer overflow vulnerability in Exim mail servers that allows remote attackers to execute arbitrary code by sending specially crafted MAIL FROM or RCPT TO comm...

CVE-2020-28024

CRITICAL CVSS 9.8 May 6, 2021

CVE-2020-28024 is a critical buffer underwrite vulnerability in Exim mail servers that allows unauthenticated remote attackers to execute arbitrary commands. The vulnerability occurs because the smtp_...

CVE-2020-28026

CRITICAL CVSS 9.8 May 6, 2021

CVE-2020-28026 is a critical vulnerability in Exim mail servers that allows unauthenticated remote attackers to execute arbitrary commands as root when Delivery Status Notification (DSN) is enabled. T...

CVE-2025-67896

HIGH CVSS 7.0 Dec 14, 2025

A heap-based buffer overflow vulnerability in Exim mail servers with certain non-default rate-limit configurations allows remote attackers to potentially execute arbitrary code or cause denial of serv...

CVE-2025-30232

HIGH CVSS 8.1 Mar 28, 2025

A use-after-free vulnerability in Exim versions 4.96 through 4.98.1 allows users with command-line access to escalate privileges. This affects systems running vulnerable Exim versions where users have...

CVE-2025-26794

HIGH CVSS 7.5 Feb 21, 2025

Exim mail servers running versions 4.98 before 4.98.1 with SQLite hints and ETRN serialization enabled are vulnerable to remote SQL injection attacks. This allows attackers to potentially execute arbi...

CVE-2021-38371

HIGH CVSS 7.5 Aug 10, 2021

This vulnerability in Exim's STARTTLS implementation allows attackers to inject malicious responses during SMTP communication by exploiting buffering issues. It affects Exim mail servers using STARTTL...

CVE-2020-28007

HIGH CVSS 7.8 May 6, 2021

CVE-2020-28007 is a privilege escalation vulnerability in Exim mail servers where an attacker can create symbolic or hard links in the log directory to overwrite critical root-owned files anywhere on ...

CVE-2020-28009

HIGH CVSS 7.8 May 6, 2021

CVE-2020-28009 is an integer overflow vulnerability in Exim mail transfer agent versions before 4.94.2. It allows remote attackers to cause buffer overflow via unbounded reads in get_stdinput function...

CVE-2020-28011

HIGH CVSS 7.8 May 6, 2021

CVE-2020-28011 is a heap-based buffer overflow vulnerability in Exim mail transfer agent versions before 4.94.2. Attackers can exploit this via the -R and -S sender options during queue processing to ...

CVE-2020-28013

HIGH CVSS 7.8 May 6, 2021

CVE-2020-28013 is a heap-based buffer overflow vulnerability in Exim mail transfer agent versions before 4.94.2. It allows local privilege escalation from any user to root by exploiting improper handl...

CVE-2020-28015

HIGH CVSS 7.8 May 6, 2021

CVE-2020-28015 is a vulnerability in Exim mail transfer agent where local users can inject newline characters into recipient addresses, potentially altering the behavior of root processes. This affect...

CVE-2020-28019

HIGH CVSS 7.5 May 6, 2021

This vulnerability in Exim mail servers allows remote attackers to cause a denial of service through stack consumption via specially crafted BDAT commands. It affects Exim installations that accept BD...

CVE-2024-39929

MEDIUM CVSS 5.4 Jul 4, 2024

This vulnerability in Exim mail servers allows attackers to bypass filename extension filtering by using specially crafted multiline RFC 2231 headers. Attackers can deliver executable attachments that...