CyberSec.Space Logo
Back to CVE Browser

CVE-2019-16928

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score48.0980%
EPSS Percentile93.37th
PublishedSep 27, 2019
Last ModifiedNov 7, 2025

Vulnerability Description

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

Affected Platforms (CPE)

πŸ“¦
Exim

Exim

>= 4.92 and <= 4.92.2
πŸ’»
Canonical

Ubuntu Linux

= 19.04
πŸ’»
Debian

Debian Linux

= 10.0
πŸ’»
Fedoraproject

Fedora

= 29
πŸ’»
Fedoraproject

Fedora

= 30
πŸ’»
Fedoraproject

Fedora

= 31

References & Advisories

Related Vulnerabilities