Back to Database
Status published
High
CVE-2025-67896
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a...
Vulnerability Description
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-67896
Credits & Attribution
No credits recorded in the NVD database.
References
More from Exim
View All →CVE-2025-30232
A use-after-free in Exim 4.96 through 4.98.1 could allow users...
High
8.1
CVE-2025-26794
Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization...
High
7.5
CVE-2023-42119
Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability
Low
3.1
CVE-2023-42118
Exim libspf2 Integer Underflow Remote Code Execution Vulnerability
High
7.5
CVE-2023-42117
Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability
High
8.1
Affected Vendor
Exim
View all reports →Affected Software
Exim
Vulnerable Versions:
4.99
Timeline
Official Publish:
December 14th, 2025
Last Modified:
December 18th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L