CVE-2020-28018: Exim
Critical severity, CVSS 9.8. EPSS: 56.5% chance of exploitation in the next 30 days.
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.
Affected products
- Exim Exim: from 4.90, before 4.94.2 (fixed in 4.94.2)
Published 2021-05-06. Last modified 2026-06-17.