Exim Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Exim products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

5

In CISA KEV

5

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Exim KEVs Added by Year

Loading...

5 Exim KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2018-6789

An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may...

Confirmed In CISA 03 Nov 2021
CVE-2019-10149

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in...

Confirmed In CISA 10 Jan 2022
CVE-2019-16928

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in...

Confirmed In CISA 03 Mar 2022
CVE-2010-4344

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an...

Confirmed In CISA 25 Mar 2022
CVE-2010-4345

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate...

Confirmed In CISA 25 Mar 2022

Common Vulnerability Classes (CWE)

  • CWE-787 — Out-of-bounds Write 2
  • CWE-120 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') 1
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology