Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

95 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)5.3%—Exim4/9/201417/6/2026
The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.
ModificadaMedia (6.8)8.4%—Exim31/10/201216/6/2026
Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn control = dkim_disable_verify," allows remote attackers to execute arbitrary code via an email from a malicious DNS server.
ModificadaAlta (7.5)3.9%—Exim5/10/201116/6/2026
Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a %…
ModificadaAlta (7.5)3.8%—Exim16/5/201116/6/2026
The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.
ModificadaMedia (6.9)0.38%—Exim2/2/201116/6/2026
The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.
AnalizadaAlta (7.8)18%⚠ Explotación activa💥 ExploitEximOpensuseDebian LinuxCanonical Ubuntu Linux14/12/201016/6/2026
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
AnalizadaCrítica (9.8)72%⚠ Explotación activa💥 ExploitEximOpensuseDebian LinuxCanonical Ubuntu Linux14/12/201016/6/2026
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
ModificadaMedia (4.4)0.28%—Exim7/6/201016/6/2026
transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.
ModificadaMedia (4.4)0.28%—Exim7/6/201016/6/2026
transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.
ModificadaMedia (5)1.5%—Sa-exim19/3/200616/6/2026
Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.
ModificadaMedia (4.6)0.72%—University OF Cambridge Exim2/5/200516/6/2026
Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.
ModificadaAlta (7.2)2.6%💥 ExploitUniversity OF Cambridge Exim2/5/200516/6/2026
Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which…
ModificadaAlta (7.5)21%💥 ExploitUniversity OF Cambridge Exim7/7/200416/6/2026
Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.
ModificadaAlta (7.5)7.0%—University OF Cambridge Exim7/7/200416/6/2026
Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.
ModificadaAlta (7.5)5.7%—University OF Cambridge Exim20/10/200316/6/2026
Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no…
ModificadaAlta (7.2)2.3%💥 ExploitUniversity OF Cambridge Exim23/12/200216/6/2026
Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.
ModificadaMedia (4.6)0.38%—University OF Cambridge Exim31/5/200216/6/2026
Exim 3.34 and earlier may allow local users to gain privileges via a buffer overflow in long -C (configuration file) and other command line arguments.
ModificadaAlta (7.5)6.4%—University OF Cambridge EximRedhat Linux19/12/200116/6/2026
Exim 3.22 and earlier, in some configurations, does not properly verify the local part of an address when redirecting the address to a pipe, which could allow remote attackers to execute arbitrary commands via shell metacharacters.
ModificadaAlta (7.5)12%💥 ExploitUniversity OF Cambridge EximConectiva LinuxDebian LinuxRedhat Linux20/9/200116/6/2026
Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.
ModificadaAlta (7.2)0.69%💥 ExploitUniversity OF Cambridge Exim22/7/199716/6/2026
Buffer overflow in Exim allows local users to gain root privileges via a long :include: option in a .forward file.
Orbitaley — Vulnerabilidades