Exim vendor intelligence
Exim Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Exim products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 5
- Known exploited vulnerabilities affecting Exim products
- In CISA KEV
- 5
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Exim KEVs with sensor-observed exploitation activity
The catalog gap matters for Exim exposure
All five exploited Exim CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
- 2
- Product families
Attested Exim CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2018-6789
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may... |
Exim | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in... |
exim | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2019-16928
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in... |
Exim | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2010-4344
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an... |
Exim | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2010-4345
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate... |
Exim | Confirmed | In CISA | 25 Mar 2022 |
No Exim CVEs match this search or filter.
Showing 5 of 5 Exim known exploited vulnerabilities.
Recurring weakness patterns
Out-of-bounds write, buffer copy without checking size, and neutralization account for four mapped occurrences across this Exim KEV portfolio.
CWE-787
Out-of-bounds Write
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.