Show filters
64 Total Results
Displaying 61-64 of 64
Sort by:
Attacker Value
Unknown
CVE-2010-4345
Disclosure Date: December 14, 2010 (last updated July 17, 2024)
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
0
Attacker Value
Unknown
CVE-2010-2024
Disclosure Date: June 07, 2010 (last updated October 04, 2023)
transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.
0
Attacker Value
Unknown
CVE-2010-2023
Disclosure Date: June 07, 2010 (last updated October 04, 2023)
transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.
0
Attacker Value
Unknown
CVE-2006-1251
Disclosure Date: March 19, 2006 (last updated February 22, 2025)
Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.
0