Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x8x4-4g6x-cx4h

Опубликовано: 01 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

EPSS

Процентиль: 30%
0.00373
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-909

Связанные уязвимости

CVSS3: 4.8
ubuntu
3 месяца назад

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

CVSS3: 4.8
nvd
3 месяца назад

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

CVSS3: 4.8
debian
3 месяца назад

In Exim before 4.99.2, when the SPA authentication driver is used with ...

CVSS3: 9.1
fstec
5 месяцев назад

Уязвимость почтового сервера Exim, связанная с отсутствием инициализации ресурса, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации

CVSS3: 9.1
redos
6 дней назад

Уязвимость exim

EPSS

Процентиль: 30%
0.00373
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-909