Claws Mail
Products
1- 11 CVEs
Recent CVEs
11| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-8708 | Hig | 0.48 | 7.3 | 0.01 | Apr 11, 2016 | Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. NOTE: this vulnerability exists because of an incomplete fix for… | ||
| CVE-2015-8614 | Hig | 0.48 | 7.3 | 0.03 | Apr 11, 2016 | Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. | ||
| CVE-2021-37746 | 0.00 | — | 0.01 | Jul 30, 2021 | textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click. | |||
| CVE-2020-16094 | 0.00 | — | 0.02 | Jul 28, 2020 | In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree. | |||
| CVE-2020-15917 | 0.00 | — | 0.03 | Jul 23, 2020 | common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled. | |||
| CVE-2012-5527 | 0.00 | — | 0.01 | Nov 25, 2019 | Claws Mail vCalendar plugin: credentials exposed on interface | |||
| CVE-2019-10735 | 0.00 | — | 0.01 | Apr 7, 2019 | In Claws Mail 3.14.1, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by… | |||
| CVE-2014-2576 | 0.00 | — | 0.02 | Oct 15, 2014 | plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks. | |||
| CVE-2012-4507 | 0.00 | — | 0.03 | Oct 22, 2012 | The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted email. | |||
| CVE-2007-6208 | 0.00 | — | 0.00 | Dec 4, 2007 | sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file. | |||
| CVE-2007-2958 | 0.00 | — | 0.03 | Aug 27, 2007 | Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies. |
- risk 0.48cvss 7.3epss 0.01
Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. NOTE: this vulnerability exists because of an incomplete fix for…
- risk 0.48cvss 7.3epss 0.03
Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.
- CVE-2021-37746Jul 30, 2021risk 0.00cvss —epss 0.01
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
- CVE-2020-16094Jul 28, 2020risk 0.00cvss —epss 0.02
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
- CVE-2020-15917Jul 23, 2020risk 0.00cvss —epss 0.03
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
- CVE-2012-5527Nov 25, 2019risk 0.00cvss —epss 0.01
Claws Mail vCalendar plugin: credentials exposed on interface
- CVE-2019-10735Apr 7, 2019risk 0.00cvss —epss 0.01
In Claws Mail 3.14.1, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by…
- CVE-2014-2576Oct 15, 2014risk 0.00cvss —epss 0.02
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
- CVE-2012-4507Oct 22, 2012risk 0.00cvss —epss 0.03
The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted email.
- CVE-2007-6208Dec 4, 2007risk 0.00cvss —epss 0.00
sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.
- CVE-2007-2958Aug 27, 2007risk 0.00cvss —epss 0.03
Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.