← Back

Mutt

mutt

Vendor: Mutt • 45 CVEs

CVEs (45)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Mutt
NeomuttRedhat
3Enterprise Linux
MuttNeomutt
Nov 14, 2024
Nov 12, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
3Mutt
NeomuttRedhat
3Enterprise Linux
MuttNeomutt
Nov 14, 2024
Nov 12, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
3Mutt
NeomuttRedhat
3Enterprise Linux
MuttNeomutt
Jul 16, 2025
Nov 12, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compr...Show more
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.Show less
2Debian
Mutt
2Debian Linux
Mutt
Nov 21, 2024
Sep 9, 2023
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
2Debian
Mutt
2Debian Linux
Mutt
Nov 21, 2024
Sep 9, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12
3Debian
FedoraprojectMutt
3Debian Linux
FedoraMutt
Nov 21, 2024
Apr 14, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
2Mutt
Neomutt
2Mutt
Neomutt
Nov 21, 2024
May 5, 2021
N/A· v4
9.1 CRITICAL· v3
5.8 MEDIUM· v2
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE...Show more
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.Show less
3Debian
FedoraprojectMutt
3Debian Linux
FedoraMutt
Nov 21, 2024
Jan 19, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of e...Show more
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons.Show less
3Debian
MuttNeomutt
3Debian Linux
MuttNeomutt
Nov 21, 2024
Nov 23, 2020
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continu...Show more
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.Show less
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLeap+3 more
Nov 21, 2024
Jun 21, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-mi...Show more
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."Show less
2Canonical
Mutt
2Mutt
Ubuntu Linux
Nov 21, 2024
Jun 15, 2020
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate.
4Canonical
DebianMutt+1 more
4Debian Linux
LeapMutt+1 more
Nov 21, 2024
Jun 15, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
2Debian
Mutt
2Debian Linux
Mutt
Nov 20, 2024
Nov 1, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
5Canonical
DebianMutt+2 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+7 more
Nov 21, 2024
Jul 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
4Canonical
DebianMutt+1 more
4Debian Linux
MuttNeomutt+1 more
Nov 21, 2024
Jul 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
4Canonical
DebianMutt+1 more
4Debian Linux
MuttNeomutt+1 more
Nov 21, 2024
Jul 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field.
5Canonical
DebianMutt+2 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+7 more
Nov 21, 2024
Jul 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an auto...Show more
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.Show less
4Canonical
DebianMutt+1 more
4Debian Linux
MuttNeomutt+1 more
Nov 21, 2024
Jul 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
4Canonical
DebianMutt+1 more
4Debian Linux
MuttNeomutt+1 more
Nov 21, 2024
Jul 17, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.
5Canonical
DebianMutt+2 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+7 more
Nov 21, 2024
Jul 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manua...Show more
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription.Show less