threat
engine
.sh
Back
·
··:··
Home
/
Product
/
neomutt
Product
neomutt
21 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2024-49395
all versions
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferrin
5.3
MEDIUM
CVE-2024-49394
all versions
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse
5.3
MEDIUM
CVE-2024-49393
all versions
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercep
6.5
MEDIUM
CVE-2021-32055
>= 20191025 and <= 20210504
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c
9.1
CRITICAL
CVE-2020-28896
< 2020-11-20
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial serve
5.3
MEDIUM
CVE-2020-14954
< 20200619
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server
5.9
MEDIUM
CVE-2018-14363
< 20180716
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe inte
7.5
HIGH
CVE-2018-14362
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe
9.8
CRITICAL
CVE-2018-14361
< 20180716
An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
9.8
CRITICAL
CVE-2018-14360
< 20180716
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of inco
9.8
CRITICAL
CVE-2018-14359
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
9.8
CRITICAL
CVE-2018-14358
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for
9.8
CRITICAL
CVE-2018-14357
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary c
9.8
CRITICAL
CVE-2018-14356
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
9.8
CRITICAL
CVE-2018-14355
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a
5.3
MEDIUM
CVE-2018-14354
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary c
9.8
CRITICAL
CVE-2018-14353
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer under
9.8
CRITICAL
CVE-2018-14352
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room
9.8
CRITICAL
CVE-2018-14351
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox
9.8
CRITICAL
CVE-2018-14350
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for
9.8
CRITICAL
CVE-2018-14349
< 20180716
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a mes
9.8
CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin