CVE-2023-4874
- EPSS 0.08%
- Veröffentlicht 09.09.2023 15:15:34
- Zuletzt bearbeitet 21.11.2024 08:36:09
Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12
CVE-2022-1328
- EPSS 0.27%
- Veröffentlicht 14.04.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:29
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
CVE-2021-32055
- EPSS 0.37%
- Veröffentlicht 05.05.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:46
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting fo...
CVE-2021-3181
- EPSS 3%
- Veröffentlicht 19.01.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 06:21:04
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email me...
CVE-2020-28896
- EPSS 0.1%
- Veröffentlicht 23.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:14
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. ...
CVE-2020-14954
- EPSS 4.79%
- Veröffentlicht 21.06.2020 17:15:09
- Zuletzt bearbeitet 21.11.2024 05:04:30
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates i...
CVE-2020-14154
- EPSS 0.69%
- Veröffentlicht 15.06.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:45
Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate.
CVE-2020-14093
- EPSS 3.86%
- Veröffentlicht 15.06.2020 05:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:36
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
CVE-2005-2351
- EPSS 0.13%
- Veröffentlicht 01.11.2019 19:15:10
- Zuletzt bearbeitet 20.11.2024 23:59:21
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
CVE-2018-14354
- EPSS 2.53%
- Veröffentlicht 17.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:53
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscripti...