VYPR

Barnowl

by Barnowl

CVEs (3)

  • CVE-2010-2725Aug 5, 2010
    risk 0.00cvss epss 0.01

    BarnOwl before 1.6.2 does not check the return code of calls to the (1) ZPending and (2) ZReceiveNotice functions in libzephyr, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

  • CVE-2010-0793Mar 16, 2010
    risk 0.00cvss epss 0.02

    Buffer overflow in BarnOwl before 1.5.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted CC: header.

  • CVE-2009-0363Feb 17, 2009
    risk 0.00cvss epss 0.04

    Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use of the products.