Known vulnerabilities in exim4 (Debian package) 4.89-2+deb9u1

Vendor: Debian
Version: 4.89-2+deb9u1
Software CPE: cpe:2.3:o:debian:exim4_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 21
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting exim4 (Debian package) version 4.89-2+deb9u1 exim4 (Debian package) 4.89-2+deb9u1 is affected by 21 vulnerabilities: 6 high, 6 medium, 9 low Critical High Medium Low

Vulnerabilities (21)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU52872 - Out-of-bounds read
CVE-2020-28025
CWE-125 Medium
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52870 - Integer underflow
CVE-2020-28024
CWE-191 High
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52869 - Resource Management Errors
CVE-2020-28019
CWE-399 Medium
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 2 more
#VU52868 - Improper input validation
CVE-2020-28026
CWE-20 Medium
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52867 - Out-of-bounds write
CVE-2020-28022
CWE-787 High
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52866 - Improper input validation
CVE-2020-28021
CWE-20 Medium
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 2 more
#VU52865 - Out-of-bounds read
CVE-2020-28023
CWE-125 Medium
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 2 more
#VU52863 - Integer overflow
CVE-2020-28017
CWE-190 High
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52862 - Integer overflow
CVE-2020-28009
CWE-190 Low
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52861 - Security Features
CVE-2020-28012
CWE-254 Low
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52860 - Improper input validation
CVE-2020-28015
CWE-20 Low
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52858 - Heap-based Buffer Overflow
CVE-2020-28013
CWE-122 Low
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52857 - Out-of-bounds write
CVE-2020-28010
CWE-787 Low
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 2 more
#VU52856 - Heap-based Buffer Overflow
CVE-2020-28011
CWE-122 Low
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52855 - Permissions, Privileges, and Access Controls
CVE-2020-28014
CWE-264 Low
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52854 - Permissions, Privileges, and Access Controls
CVE-2020-28008
CWE-264 Low
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU52853 - UNIX Symbolic Link (Symlink) Following
CVE-2020-28007
CWE-61 Low
No
No
4.92-8+deb10u6 04.05.2021 SB2021050419
SB2021050420
SB2021050421
and 3 more
#VU27959 - Out-of-bounds read
CVE-2020-12783
CWE-125 Medium
No
No
4.89-2+deb9u7, 4.92-8+deb10u4 18.05.2020 SB2020051804
SB2020051805
SB2020052108
and 7 more
#VU20924 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-15846
CWE-78 High
Public exploit available
No
4.89-2+deb9u6, 4.92-8+deb10u2 06.09.2019 SB2019090614
SB2019090615
SB2019090616
and 11 more
#VU19368 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-13917
CWE-78 High
No
No
4.89-2+deb9u5 25.07.2019 SB2019072502
SB2019072503
SB2019072601
and 3 more


Showing elements 1 - 20 out of 21