ZeroHour

Vulnerabilities

63 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-66140
+1 in the same advisory: …66141
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-na

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

NVD description · AI analysis pending
7.8<1%
  • exim exim
CVE-2026-48840
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client

Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.

NVD description · AI analysis pending
5.3<1%
  • exim exim
CVE-2026-45185
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path.

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

NVD description · AI analysis pending
9.81%
  • exim exim
CVE-2026-40685
+3 in the same advisory: …40687 …40684 …40686
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header,

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

NVD description · AI analysis pending
9.8
group max
<1%
  • exim exim
CVE-2025-67896
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

NVD description · AI analysis pending
9.8<1%
  • exim exim
CVE-2025-30232
A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.

A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.

NVD description · AI analysis pending
7.8<1%
  • exim exim
CVE-2025-26794
Critical Unauthenticated SQL Injection in Exim 4.98

Exim, the widely deployed open-source mail transfer agent, is vulnerable to remote SQL injection (CVE-2025-26794, CWE-89) in version 4.98 before 4.98.1. The flaw is reachable over the network when a server uses SQLite for its hints database together with ETRN serialization, and per the CVSS vector requires no privileges or user interaction, with high impact on confidentiality, integrity, and availability. A successful attacker could manipulate the SQLite-backed data Exim relies on and disrupt mail handling, consistent with the critical 9.8 score. Only sites running Exim 4.98.x on affected configurations are exposed; sites with certain non-default rate-limit configurations need version 4.99.1 for the SQL injection to be fully resolved. No public proof-of-concept or CISA KEV entry exists yet, but EPSS assigns a 77.2% probability of exploitation within 30 days (100th percentile), so patching should be treated as urgent.

Do: Upgrade Exim to 4.98.1 or later; sites using certain non-default rate-limit configurations should move to 4.99.1, since the SQL injection is only fully resolved there. Administrators should check whether their configuration uses SQLite for the hints database and ETRN serialization, and until patching can mitigate by disabling SQLite hints/ETRN serialization or restricting network access to the SMTP service. Given the 77.2% EPSS score, treat this as a priority patch even though exploitation has not yet been confirmed.

9.877%
  • Exim 4.98 before 4.98.1 (only when SQLite hints and ETRN serialization are used; certain non-default rate-limit configurations require 4.99.1 for full resolution)
largelikely on the order of tens of thousands of mail servers (a configured subset of Exim's 1M+ installed base)
CVE-2024-39929
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanis

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

NVD description · AI analysis pending
5.441% PoC
  • exim exim
CVE-2023-42115
+4 in the same advisory: …42117 …42116 …42114 …42119
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability.

Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of a buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17434.

NVD description · AI analysis pending
9.8
group max
10%
  • exim exim
CVE-2023-51766
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations.

Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports . but some other popular e-mail servers do not.

NVD description · AI analysis pending
5.31% PoC
  • exim exim
  • exim extra packages for enterprise linux
  • exim fedora
  • +1 more
CVE-2022-4523
A vulnerability, which was classified as problematic, has been found in vexim2.

A vulnerability, which was classified as problematic, has been found in vexim2. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 21c0a60d12e9d587f905cd084b2c70f9b1592065. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215903.

NVD description · AI analysis pending
6.1<1%
  • virtual exim project virtual exim 2
CVE-2022-3620
A vulnerability was found in Exim and classified as problematic.

A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. The manipulation leads to use after free. The attack may be initiated remotely. The name of the patch is 12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211919.

NVD description · AI analysis pending
9.8<1%
  • exim exim
  • exim fedora
CVE-2022-3559
A vulnerability was found in Exim and classified as problematic.

A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulnerability.

NVD description · AI analysis pending
7.54%
  • exim exim
  • exim fedora
CVE-2022-37452
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

NVD description · AI analysis pending
9.84% PoC
  • exim exim
  • exim debian linux
CVE-2022-37451
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.

Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.

NVD description · AI analysis pending
7.53% PoC
  • exim exim
  • exim fedora
CVE-2021-38371
The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.

The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.

NVD description · AI analysis pending
7.52%
  • exim exim
CVE-2020-28018
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.

Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.

NVD description · AI analysis pending
9.8
group max
57%
  • exim exim
CVE-2020-12783
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.

Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.

NVD description · AI analysis pending
7.55% PoC
  • exim exim
  • exim fedora
  • exim debian linux
  • +1 more
CVE-2020-8015
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root.

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: openSUSE Factory exim versions prior to 4.93.0.4-3.1.

NVD description · AI analysis pending
7.8<1% PoC
  • exim exim
CVE-2019-19920
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule.

sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.

NVD description · AI analysis pending
8.83%
  • sa-exim project sa-exim
  • sa-exim project ubuntu linux
  • sa-exim project debian linux
CVE-2019-18820
+1 in the same advisory: …18821
Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.

Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.

NVD description · AI analysis pending
5.5<1% PoC
  • eximioussoft logo designer