Search CVE reports


Toggle filters

1 – 10 of 70 results


CVE-2026-40687

Medium priority
Needs evaluation

Possible OOB read/write with SPA authenticator

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40686

Medium priority
Needs evaluation

Possible OOB read with large UTF8 trailing characters

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40685

Medium priority
Needs evaluation

Possible OOB read/write on corrupt JSON in header

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40684

Medium priority
Not affected

Possible crash with malicious DNS data when using musl libc

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-67896

High priority
Not affected

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-53881

Medium priority
Not affected

A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumbleweed: from ? before 4.98.2-lp156.248.1.

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-30232

Medium priority
Fixed

A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-26794

Medium priority
Not affected

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-39929

Medium priority

Some fixes available 5 of 6

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of...

1 affected package

exim4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-42118

Medium priority
Vulnerable

Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim libspf2. Authentication is not required to...

2 affected packages

exim4, libspf2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exim4 Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
libspf2 Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages