peter bassill · operator
$ cve CVE-2002-1381 JSON

CVE-2002-1381 EXPLOIT

7.2
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.

Scoring

CVSS7.2 (HIGH, v2.0)
VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS2.3% — more likely to be exploited than 83% of all CVEs
On CISA KEVno
Public exploityes
Published2002-12-23
Last modified2026-06-16

Affected (1)

VendorProduct
university of cambridgeexim

Public exploits

SourceTitleDate
exploit-dbExim Internet Mailer 3.35/3.36/4.10 - Format String2002-12-04

References

→ the Explorer  ·  watch your stack  ·  NVD