Search CVE reports
21 – 30 of 38 results
CVE-2018-14353
Medium prioritySome fixes available 16 of 19
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Fixed | Fixed | Fixed | Fixed | Fixed |
neomutt | Not affected | Not affected | Not affected | Vulnerable | Not in release |
CVE-2018-14352
Medium prioritySome fixes available 16 of 19
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Fixed | Fixed | Fixed | Fixed | Fixed |
neomutt | Not affected | Not affected | Not affected | Vulnerable | Not in release |
CVE-2018-14351
Medium prioritySome fixes available 16 of 19
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Fixed | Fixed | Fixed | Fixed | Fixed |
neomutt | Not affected | Not affected | Not affected | Vulnerable | Not in release |
CVE-2018-14350
Medium prioritySome fixes available 16 of 19
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long INTERNALDATE field.
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Fixed | Fixed | Fixed | Fixed | Fixed |
neomutt | Not affected | Not affected | Not affected | Vulnerable | Not in release |
CVE-2018-14349
Medium prioritySome fixes available 16 of 19
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.
2 affected packages
mutt, neomutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | Fixed | Fixed | Fixed | Fixed | Fixed |
neomutt | Not affected | Not affected | Not affected | Vulnerable | Not in release |
CVE-2014-9116
Medium priorityThe write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which...
1 affected packages
mutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | — | — | — | — | — |
CVE-2014-0467
Medium priorityBuffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
1 affected packages
mutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | — | — | — | — | — |
CVE-2011-1429
Medium prioritySome fixes available 3 of 5
Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different...
1 affected packages
mutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | — | — | — | — | — |
CVE-2009-3766
Negligible prioritymutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof...
1 affected packages
mutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | — | — | — | — | — |
CVE-2009-3765
Negligible prioritymutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to...
1 affected packages
mutt
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mutt | — | — | — | — | — |