CVE-2020-14154
- EPSS 0.66%
- Published 15.06.2020 17:15:10
- Last modified 21.11.2024 05:02:45
Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate.
CVE-2020-14093
- EPSS 2.12%
- Published 15.06.2020 05:15:11
- Last modified 21.11.2024 05:02:36
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
CVE-2005-2351
- EPSS 0.13%
- Published 01.11.2019 19:15:10
- Last modified 20.11.2024 23:59:21
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
CVE-2018-14351
- EPSS 1.35%
- Published 17.07.2018 17:29:00
- Last modified 21.11.2024 03:48:53
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.
CVE-2018-14362
- EPSS 4.42%
- Published 17.07.2018 17:29:00
- Last modified 21.11.2024 03:48:55
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
CVE-2018-14359
- EPSS 4.08%
- Published 17.07.2018 17:29:00
- Last modified 21.11.2024 03:48:54
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
CVE-2018-14358
- EPSS 1.85%
- Published 17.07.2018 17:29:00
- Last modified 21.11.2024 03:48:54
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field.
CVE-2018-14357
- EPSS 3.31%
- Published 17.07.2018 17:29:00
- Last modified 21.11.2024 03:48:54
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.
CVE-2018-14356
- EPSS 0.91%
- Published 17.07.2018 17:29:00
- Last modified 21.11.2024 03:48:54
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
CVE-2018-14355
- EPSS 0.44%
- Published 17.07.2018 17:29:00
- Last modified 21.11.2024 03:48:54
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.