CVE-2014-2957: Exim
Medium severity, CVSS 6.8. EPSS: 5.3% chance of exploitation in the next 30 days.
The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.
Affected products
- Exim Exim: up to and including 4.82; version 4.00 only; version 4.01 only; version 4.02 only; version 4.03 only; version 4.04 only; …
Published 2014-09-04. Last modified 2026-06-17.