Show filters
70 Total Results
Displaying 31-40 of 70
Sort by:
Attacker Value
Unknown
CVE-2020-28012
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Exim 4 before 4.94.2 allows Exposure of File Descriptor to Unintended Control Sphere because rda_interpret uses a privileged pipe that lacks a close-on-exec flag.
0
Attacker Value
Unknown
CVE-2020-28015
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processes because a recipient address can have a newline character.
0
Attacker Value
Unknown
CVE-2020-28017
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: remote exploitation may be difficult because of resource consumption.
0
Attacker Value
Unknown
CVE-2020-28011
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queue_run via two sender options: -R and -S. This may cause privilege escalation from exim to root.
0
Attacker Value
Unknown
CVE-2020-28020
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by leveraging the mishandling of continuation lines during header-length restriction.
0
Attacker Value
Unknown
CVE-2020-28009
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads that are accompanied by unbounded increases in a certain size variable. NOTE: exploitation may be impractical because of the execution time needed to overflow (multiple days).
0
Attacker Value
Unknown
CVE-2020-28025
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Exim 4 before 4.94.2 allows Out-of-bounds Read because pdkim_finish_bodyhash does not validate the relationship between sig->bodyhash.len and b->bh.len; thus, a crafted DKIM-Signature header might lead to a leak of sensitive information from process memory.
0
Attacker Value
Unknown
CVE-2020-12783
Disclosure Date: May 11, 2020 (last updated February 21, 2025)
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.
0
Attacker Value
Unknown
CVE-2020-8015
Disclosure Date: April 02, 2020 (last updated February 21, 2025)
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of exim in openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: openSUSE Factory exim versions prior to 4.93.0.4-3.1.
0
Attacker Value
Unknown
CVE-2019-19920
Disclosure Date: December 22, 2019 (last updated November 27, 2024)
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
0