CyberSec.Space Logo
Back to CVE Browser

CVE-2010-4344

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score82.0680%
EPSS Percentile86.90th
PublishedDec 14, 2010
Last ModifiedApr 21, 2026

Vulnerability Description

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

Affected Platforms (CPE)

πŸ“¦
Exim

Exim

< 4.70
πŸ’»
Opensuse

Opensuse

= 11.1
πŸ’»
Opensuse

Opensuse

= 11.2
πŸ’»
Opensuse

Opensuse

= 11.3
πŸ’»
Debian

Debian Linux

= 5.0
πŸ’»
Canonical

Ubuntu Linux

= 6.06
πŸ’»
Canonical

Ubuntu Linux

= 8.04
πŸ’»
Canonical

Ubuntu Linux

= 9.10

References & Advisories

Related Vulnerabilities