Search CVE reports


Toggle filters

31 – 40 of 47 results


CVE-2018-14352

Medium priority

Some fixes available 17 of 19

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.

2 affected packages

mutt, neomutt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mutt Fixed Fixed Fixed Fixed
neomutt Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-14351

Medium priority

Some fixes available 17 of 19

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.

2 affected packages

mutt, neomutt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mutt Fixed Fixed Fixed Fixed
neomutt Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-14350

Medium priority

Some fixes available 17 of 19

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long INTERNALDATE field.

2 affected packages

mutt, neomutt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mutt Fixed Fixed Fixed Fixed
neomutt Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-14349

Medium priority

Some fixes available 17 of 19

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.

2 affected packages

neomutt, mutt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
neomutt Not affected Not affected Not affected Fixed
mutt Fixed Fixed Fixed Fixed
Show less packages

CVE-2014-9116

Medium priority
Fixed

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which...

1 affected package

mutt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mutt
Show less packages

CVE-2014-0467

Medium priority
Fixed

Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.

1 affected package

mutt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mutt
Show less packages

CVE-2011-1429

Medium priority

Some fixes available 3 of 5

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different...

1 affected package

mutt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mutt
Show less packages

CVE-2009-3766

Negligible priority
Ignored

mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof...

1 affected package

mutt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mutt
Show less packages

CVE-2009-3765

Negligible priority
Ignored

mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to...

1 affected package

mutt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mutt
Show less packages

CVE-2009-1390

Medium priority
Not affected

Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote...

1 affected package

mutt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mutt
Show less packages