Exim
8 known vulnerabilities
Top Products
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privilege
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of unini
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing p
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-
In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing character
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounter
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malfor
Frequently Asked Questions
How many CVEs affect Exim?
Exim has 8 CVE records in our database, including 1 critical and 2 high severity vulnerabilities.
What are the most severe Exim vulnerabilities?
Exim has 1 critical severity (CVSS 9.0+) and 2 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Exim vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Exim products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Exim Vulnerabilities
CyberStrike scans your infrastructure for Exim vulnerabilities and provides real-time remediation guidance.
Get Started