Exim Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Exim products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
5
In CISA KEV
5
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
Exim KEVs Added by Year
5 Exim KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2018-6789
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may... |
Exim | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in... |
exim | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2019-16928
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in... |
Exim | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2010-4344
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an... |
Exim | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2010-4345
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate... |
Exim | Confirmed | In CISA | 25 Mar 2022 |
Common Vulnerability Classes (CWE)
- CWE-787 — Out-of-bounds Write 2
- CWE-120 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') 1
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology