VYPR

Johnny-You-Are-Fired

by RUB NDS

CVEs (5)

  • CVE-2018-15588HigFeb 11, 2019
    risk 0.49cvss 7.5epss 0.02

    MailMate before 1.11.3 mishandles a suspicious HTML/MIME structure in a signed/encrypted email.

  • CVE-2017-17848HigDec 27, 2017
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually displayed. In other words, the entire containing…

  • CVE-2018-15586MedFeb 11, 2019
    risk 0.42cvss 6.5epss 0.01

    Enigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages using a PGP/INLINE signature wrapped within a specially crafted multipart HTML email.

  • CVE-2019-8338MedMay 16, 2019
    risk 0.38cvss 5.9epss 0.02

    The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, which allows remote attackers to spoof arbitrary email signatures by crafting a signed email with an invalid signature. Also, it…

  • CVE-2018-18509MedApr 26, 2019
    risk 0.35cvss 5.3epss 0.02

    A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an…