Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Exim

First CVE: Jun 7, 2010Active for: 16 yearsTotal CVEs: 67
79.7
VTI Score
TOP TARGET

Exim is a widely deployed open-source mail transfer agent that handles message routing and delivery across many server environments, placing it in a critical position within email infrastructure despite its narrow product focus. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have demonstrated a moderate tendency toward confirmed in-the-wild exploitation and public exploit availability, reflecting both the attack surface inherent to network-facing mail processing and the incentive for widespread weaponization. The recurring exposure concentrates on memory-safety and concurrency issues—out-of-bounds writes and reads, use-after-free conditions, and race conditions in shared resource handling—that are characteristic of Exim's C codebase and its role parsing untrusted message content from the network. Defenders should treat Exim updates as urgent and maintain strict visibility over internet-reachable instances, as flaws in mail servers have historically propagated rapidly across deployed infrastructure. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
67
Total CVEs
More Total CVEs than 99% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
7.5%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Exim over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2010
16 years ago
Most Recent CVE
Jul 24, 2026
0 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (67 CVEs).

67 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-10149CRITICAL
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command exec
Jun 5, 20199.898YESYES
CVE-2018-6789CRITICAL
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to exec
Feb 8, 20189.897YESYES
CVE-2010-4344CRITICAL
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MA
Dec 14, 20109.897YESYES
CVE-2019-16928CRITICAL
Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving
Sep 27, 20199.886YESNO
CVE-2010-4345HIGH
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that cont
Dec 14, 20107.886YESYES
CVE-2025-26794CRITICAL
Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-defaul
Feb 21, 20259.874NONO
CVE-2017-16944HIGH
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors
Nov 25, 20177.571NOYES
CVE-2020-28018CRITICAL
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.
May 6, 20219.862NONO
CVE-2020-28019HIGH
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mish
May 6, 20217.556NONO
CVE-2017-16943CRITICAL
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via v
Nov 25, 20179.856NONO
View all 67 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products67 CVEs
22%
42%
34%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local18 (26.9%)
Network39 (58.2%)
Unknown8 (11.9%)
Physical0 (0.0%)
Adjacent Network2 (3.0%)
Attack Complexity
Low54 (80.6%)
High5 (7.5%)
Unknown8 (11.9%)
User Interaction
None58 (86.6%)
Unknown8 (11.9%)
Required1 (1.5%)
Privileges Required
Low16 (23.9%)
High0 (0.0%)
None43 (64.2%)
Unknown8 (11.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (67 CVEs).

CISA KEV
5 CVEs
7.5% of CVEs· 100th percentile
Metasploit
4 CVEs
6.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
9.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Exim.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Exim — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Exim's Products

View all 6 CNAs →

Top CWEs