Search CVE reports


Toggle filters

1 – 10 of 71 results


CVE-2026-45185

High priority

Some fixes available 4 of 8

A remotely reachable Use-After-Free (UAF) vulnerability has been identified in Exim's BDAT (binary data transmission) body parsing path when using the GnuTLS backend. This vulnerability can lead to heap corruption and potential...

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-40687

Medium priority

Some fixes available 4 of 8

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from...

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-40686

Medium priority

Some fixes available 4 of 8

In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced...

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-40685

Medium priority

Some fixes available 4 of 8

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-40684

Medium priority
Not affected

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-67896

High priority
Not affected

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-53881

Medium priority
Not affected

A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumbleweed: from ? before 4.98.2-lp156.248.1.

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-30232

Medium priority
Fixed

A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-26794

Medium priority
Not affected

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-39929

Medium priority

Some fixes available 5 of 6

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of...

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Fixed Fixed Fixed Fixed
Show less packages