CVEs (45)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Mutt NeomuttRedhat3Enterprise Linux MuttNeomuttNov 14, 2024 Nov 12, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info. |
3Mutt NeomuttRedhat3Enterprise Linux MuttNeomuttNov 14, 2024 Nov 12, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender. |
3Mutt NeomuttRedhat3Enterprise Linux MuttNeomuttJul 16, 2025 Nov 12, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compr...Show more |
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12 |
Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12 |
3Debian FedoraprojectMutt3Debian Linux FedoraMuttNov 21, 2024 Apr 14, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line |
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE...Show more |
3Debian FedoraprojectMutt3Debian Linux FedoraMuttNov 21, 2024 Jan 19, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of e...Show more |
3Debian MuttNeomutt3Debian Linux MuttNeomuttNov 21, 2024 Nov 23, 2020 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continu...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreNov 21, 2024 Jun 21, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-mi...Show more |
2Canonical Mutt2Mutt Ubuntu LinuxNov 21, 2024 Jun 15, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate. |
4Canonical DebianMutt+1 more4Debian Linux LeapMutt+1 moreNov 21, 2024 Jun 15, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response. |
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files. |
5Canonical DebianMutt+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 21, 2024 Jul 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character. |
4Canonical DebianMutt+1 more4Debian Linux MuttNeomutt+1 moreNov 21, 2024 Jul 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data. |
4Canonical DebianMutt+1 more4Debian Linux MuttNeomutt+1 moreNov 21, 2024 Jul 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field. |
5Canonical DebianMutt+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 21, 2024 Jul 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an auto...Show more |
4Canonical DebianMutt+1 more4Debian Linux MuttNeomutt+1 moreNov 21, 2024 Jul 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID. |
4Canonical DebianMutt+1 more4Debian Linux MuttNeomutt+1 moreNov 21, 2024 Jul 17, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name. |
5Canonical DebianMutt+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 21, 2024 Jul 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manua...Show more |