Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-66140

Опубликовано: 24 июл. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 8.4

Описание

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

РелизСтатусПримечание
devel

needed

esm-infra-legacy/trusty

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

released

4.95-4ubuntu2.11
noble

released

4.97-4ubuntu4.7
resolute

released

4.99.1-1ubuntu1.4
upstream

released

4.99.4-2

Показывать по

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
redhat
8 дней назад

A flaw was found in Exim. This vulnerability allows an attacker to perform directory traversal by mishandling arguments related to queue-name. This could enable unauthorized access to files outside of the designated spool area, potentially leading to a gain of privileges.

CVSS3: 8.4
nvd
8 дней назад

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

CVSS3: 8.4
debian
8 дней назад

Exim before 4.99.5 allows directory traversal to access files outside ...

CVSS3: 8.4
github
8 дней назад

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

8.4 High

CVSS3