Home/Product/neomutt
Product

neomutt

21 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-49395
all versions
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferrin
5.3MEDIUM
CVE-2024-49394
all versions
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse
5.3MEDIUM
CVE-2024-49393
all versions
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercep
6.5MEDIUM
CVE-2021-32055
>= 20191025 and <= 20210504
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c
9.1CRITICAL
CVE-2020-28896
< 2020-11-20
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial serve
5.3MEDIUM
CVE-2020-14954
< 20200619
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server
5.9MEDIUM
CVE-2018-14363
< 20180716
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe inte
7.5HIGH
CVE-2018-14362
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe
9.8CRITICAL
CVE-2018-14361
< 20180716
An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
9.8CRITICAL
CVE-2018-14360
< 20180716
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of inco
9.8CRITICAL
CVE-2018-14359
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
9.8CRITICAL
CVE-2018-14358
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for
9.8CRITICAL
CVE-2018-14357
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary c
9.8CRITICAL
CVE-2018-14356
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
9.8CRITICAL
CVE-2018-14355
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a
5.3MEDIUM
CVE-2018-14354
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary c
9.8CRITICAL
CVE-2018-14353
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer under
9.8CRITICAL
CVE-2018-14352
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room
9.8CRITICAL
CVE-2018-14351
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox
9.8CRITICAL
CVE-2018-14350
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for
9.8CRITICAL
CVE-2018-14349
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a mes
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin