Claws-mail

Claws-mail

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.48%
  • Veröffentlicht 30.07.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 06:15:51

textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.

Exploit
  • EPSS 0.49%
  • Veröffentlicht 28.07.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:06:45

In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.

  • EPSS 2.24%
  • Veröffentlicht 23.07.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:06:26

common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.

  • EPSS 1%
  • Veröffentlicht 11.04.2016 21:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. NOTE: this vulnerability exists because...

  • EPSS 1.39%
  • Veröffentlicht 11.04.2016 21:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese ch...

  • EPSS 0.67%
  • Veröffentlicht 15.10.2014 14:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

  • EPSS 2.22%
  • Veröffentlicht 22.10.2012 23:55:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted email.