Back

CVE-2002-1381

Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.

Published: Dec 23, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
university_of_cambridge exim 3.35
university_of_cambridge exim 3.36
university_of_cambridge exim 4.10

GitHub Security Advisory GHSA-qggr-hj4x-gf78

Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 2.30%

Top 18% most likely to be exploited

Threat Score 29.5 / 100

Data Sources

NVD EPSS GitHub