Search CVE reports
11 – 20 of 47 results
Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12
1 affected package
mutt
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mutt | — | — | Fixed | Fixed | Fixed |
Some fixes available 16 of 20
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
2 affected packages
mutt, neomutt
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mutt | Fixed | Fixed | Fixed | Fixed | Fixed |
| neomutt | Not affected | Not affected | Fixed | Fixed | Fixed |
Some fixes available 3 of 11
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the...
2 affected packages
mutt, neomutt
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mutt | — | Not affected | Not affected | Fixed | Not affected |
| neomutt | — | Not affected | Not affected | Fixed | Not affected |
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of...
1 affected package
mutt
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mutt | — | — | — | Fixed | Fixed |
Some fixes available 6 of 7
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue...
2 affected packages
mutt, neomutt
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mutt | — | Not affected | Not affected | Fixed | Fixed |
| neomutt | — | Not affected | Not affected | Fixed | Fixed |
Some fixes available 6 of 7
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a...
2 affected packages
mutt, neomutt
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mutt | — | Not affected | Not affected | Fixed | Fixed |
| neomutt | — | Not affected | Not affected | Fixed | Fixed |
Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate.
1 affected package
mutt
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mutt | — | — | — | Fixed | Fixed |
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
1 affected package
mutt
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mutt | — | — | — | Fixed | Fixed |
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
1 affected package
mutt
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mutt | — | — | — | — | — |
Some fixes available 1 of 2
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
1 affected package
neomutt
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| neomutt | — | Not affected | Not affected | Not affected | Fixed |