VYPR

Airmail

by Bloop

CVEs (3)

  • CVE-2017-17689MedMay 16, 2018
    risk 0.39cvss 5.9epss 0.04

    The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

  • CVE-2017-17688MedMay 16, 2018
    risk 0.39cvss 5.9epss 0.06

    The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature…

  • CVE-2018-15670MedAug 21, 2018
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that OpenURL is the default URL handler. A navigation request is processed by the default URL…