« Volver al listado

Mutt

Mutt: vulnerabilidades y CVE

Mutt tiene 51 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE51
Últimos 12 meses6
Críticas12
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-43864Baja (2.5)0.12%—4 may 2026
mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.
CVE-2026-43863Baja (3.7)0.32%—4 may 2026
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
CVE-2026-43862Baja (3.7)0.26%—4 may 2026
In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
CVE-2026-43861Baja (3.7)0.26%—4 may 2026
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
CVE-2026-43860Baja (3.7)0.26%—4 may 2026
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
CVE-2026-43859Baja (3.7)0.26%—4 may 2026
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
CVE-2024-49395Media (5.3)0.30%—12 nov 2024
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
CVE-2024-49394Media (5.3)0.33%—12 nov 2024
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
CVE-2024-49393Media (5.9)0.33%—12 nov 2024
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to…
CVE-2023-4875Media (5.7)0.55%—9 sept 2023
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
CVE-2023-4874Media (6.5)0.85%—9 sept 2023
Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12
CVE-2022-1328Media (5.3)1.7%—14 abr 2022
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
CVE-2021-32055Crítica (9.1)2.6%—5 may 2021
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma.…
CVE-2021-3181Media (6.5)2.8%—19 ene 2021
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of…
CVE-2020-28896Media (5.3)2.4%—23 nov 2020
Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could…
CVE-2020-14954Media (5.9)2.3%—21 jun 2020
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a…
CVE-2020-14154Media (4.8)1.1%—15 jun 2020
Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate.
CVE-2020-14093Media (5.9)2.1%—15 jun 2020
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
CVE-2005-2351Media (5.5)0.35%—1 nov 2019
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
CVE-2018-14362Crítica (9.8)3.7%—17 jul 2018
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
CVE-2018-14359Crítica (9.8)4.1%—17 jul 2018
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
CVE-2018-14358Crítica (9.8)3.9%—17 jul 2018
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field.
CVE-2018-14357Crítica (9.8)5.0%—17 jul 2018
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an…
CVE-2018-14356Crítica (9.8)3.2%—17 jul 2018
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
CVE-2018-14355Media (5.3)3.3%—17 jul 2018
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.
CVE-2018-14354Crítica (9.8)6.2%—17 jul 2018
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a…
CVE-2018-14353Crítica (9.8)3.7%—17 jul 2018
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.
CVE-2018-14352Crítica (9.8)4.0%—17 jul 2018
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.
CVE-2018-14351Crítica (9.8)3.2%—17 jul 2018
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.
CVE-2018-14350Crítica (9.8)5.0%—17 jul 2018
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long INTERNALDATE field.

Otros productos de Mutt