CVE-2020-28017: Exim
Critical severity, CVSS 9.8. EPSS: 36.9% chance of exploitation in the next 30 days.
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: remote exploitation may be difficult because of resource consumption.
Affected products
- Exim Exim: before 4.94.1 (fixed in 4.94.1)
Published 2021-05-06. Last modified 2026-06-17.