Known vulnerabilities in exim (Alpine package)

Software CPE: cpe:2.3:o:alpine:exim_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 10
Public exploits: 4
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting exim (Alpine package) exim (Alpine package) is affected by 10 known vulnerabilities: 6 high, 2 medium, 2 low Critical High Medium Low

Vulnerabilities (10)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU27959 - Out-of-bounds read
CVE-2020-12783
CWE-125 Medium
No
No
4.93-r1, 4.94-r0 18.05.2020 SB2020051804
SB2020051805
SB2020052108
and 7 more
#VU21399 - Heap-based Buffer Overflow
CVE-2019-16928
CWE-122 High
No
Exploited
4.92.2-r1, 4.92.3-r0 28.09.2019 SB2019092805
SB2019092806
SB2019092807
and 11 more
#VU20924 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-15846
CWE-78 High
Available
No
4.91-r2 06.09.2019 SB2019090614
SB2019090615
SB2019090616
and 11 more
#VU19368 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-13917
CWE-78 High
No
No
4.92.1-r0 25.07.2019 SB2019072502
SB2019072503
SB2019072601
and 3 more
#VU18686 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-10149
CWE-78 High
Available
Exploited
4.91-r2 05.06.2019 SB2019060505
SB2019060506
SB2019060601
and 4 more
#VU10442 - Buffer overflow
CVE-2018-6789
CWE-120 High
Available
Exploited
4.90.1-r0 09.02.2018 SB2018020911
SB2018021101
SB2018021206
and 13 more
#VU9428 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2017-16944
CWE-835 Low
No
No
4.89.1-r0 28.11.2017 SB2017112805
SB2017112912
SB2017113009
and 8 more
#VU9427 - Use After Free
CVE-2017-16943
CWE-416 High
No
No
4.89-r7, 4.89.1-r0 28.11.2017 SB2017112803
SB2017112804
SB2017113009
and 13 more
#VU7136 - Memory corruption
CVE-2017-1000369
CWE-119 Medium
No
No
4.89-r5 21.06.2017 SB2017062102
SB2017062103
SB2017083110
and 8 more
#VU34 - Use of Potentially Dangerous Function
CVE-2016-1531
CWE-250 Low
Available
No
4.86.2-r0 28.06.2016 SB2016030302
SB2017083110
SB2016031002
and 7 more