VYPR

Claws Mail

by Claws Mail

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2014-25760.000.01Oct 15, 2014plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
CVE-2012-45070.000.01Oct 22, 2012The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted email.