Claws Mail
claws_mail
10 CVEs • 4 products
Products (4)
Click to collapseToggle
Products (4)
Click to collapse
CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Claws Mail FedoraprojectSylpheed Project3Claws Mail FedoraSylpheedNov 21, 2024 Jul 30, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click. |
2Claws Mail Fedoraproject2Claws Mail FedoraNov 21, 2024 Jul 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree. |
3Claws Mail FedoraprojectOpensuse4Backports Sle Claws MailFedora+1 moreNov 21, 2024 Jul 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled. |
Claws Mail vCalendar plugin: credentials exposed on interface |
In Claws Mail 3.14.1, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline c...Show more |
Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. NOTE: thi...Show more |
2Claws Mail Opensuse3Claws Mail LeapOpensuseMay 6, 2026 Apr 11, 2016 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafte...Show more |
2Claws Mail Opensuse2Claws Mail OpensuseMay 6, 2026 Oct 15, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM)...Show more |
The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted email. |
sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file. |