Skip to main content

Vendor/product archive

university_of_cambridge / exim CVEs

Beta · best-effort

9 CVEs tagged to university_of_cambridge / exim0 Critical, 7 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2005-0021

Published May 2, 2005

Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be comm…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0022

Published May 2, 2005

Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0399

Published Jul 7, 2004

Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly exe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0400

Published Jul 7, 2004

Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0743

Published Oct 20, 2003

Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1381

Published Dec 23, 2002

Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0274

Published May 31, 2002

Exim 3.34 and earlier may allow local users to gain privileges via a buffer overflow in long -C (configuration file) and other command line arguments.

CVSS 4.6 · Medium
Buzz score
12.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0889

Published Dec 19, 2001

Exim 3.22 and earlier, in some configurations, does not properly verify the local part of an address when redirecting the address to a pipe, which could allow remote attackers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1