Home
HIGH: 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:LDefault status
unknown
4.99 (custom) before 4.99.1
affected
Description
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
Problem types
CWE-122 Heap-based Buffer Overflow
Product status
4.99 (custom) before 4.99.1
References
www.openwall.com/lists/oss-security/2025/12/14/1
www.openwall.com/lists/oss-security/2025/12/18/3
www.openwall.com/lists/oss-security/2025/12/11/2
exim.org/...c/security/EXIM-Security-2025-12-09.1/report.txt
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.