CVE-2020-28023: Exim
High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.
Exim 4 before 4.94.2 allows Out-of-bounds Read. smtp_setup_msg may disclose sensitive information from process memory to an unauthenticated SMTP client.
Affected products
- Exim Exim: from 4.00, before 4.94.2 (fixed in 4.94.2)
Published 2021-05-06. Last modified 2026-06-17.