Lucene search

K
cvelistRedhatCVELIST:CVE-2010-4344
HistoryDec 14, 2010 - 3:00 p.m.

CVE-2010-4344

2010-12-1415:00:00
redhat
www.cve.org
1

9.8 High

AI Score

Confidence

High

0.931 High

EPSS

Percentile

99.1%

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

References