CVE-2010-4344
Exim
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
- CVSS
- 9.8
- EPSS
- 71.9% 99.4% percentile
- CISA KEV
- Listed
- Published
- 2010.12.15