VYPR

Tutanota

by Tuta

CVEs (3)

  • CVE-2024-23655HigJan 25, 2024
    risk 0.49cvss 7.5epss 0.01

    Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to send a manipulated email so that the user can no longer use the app to get access to received emails. By sending a manipulated email, an attacker could put the…

  • CVE-2024-23330MedJan 23, 2024
    risk 0.34cvss 5.3epss 0.00

    Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is loaded from external resource in the default setting, which should prevent loading of external resources. When displaying emails containing external content,…

  • CVE-2023-46116CriDec 15, 2023
    risk 0.00cvss 9.3epss 0.01

    Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applications. Prior to version 3.118.12, it correctly blocks the `file:` URL scheme, which can be used by malicious actors to gain code execution on a victims computer,…