Debian Libphp-Phpmailer vulnerabilities

12 known vulnerabilities affecting debian/libphp-phpmailer.

Total CVEs
12
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH5MEDIUM3LOW3

Vulnerabilities

Page 1 of 1
CVE-2021-3603HIGHCVSS 8.1fixed in libphp-phpmailer 6.6.3-1 (bookworm)2021
CVE-2021-3603 [HIGH] CVE-2021-3603: libphp-phpmailer - PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted... PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddress() is set to 'php' (the default, defined by PHPMailer::$validator), and the global namespace contains a function called php, it will be cal
debian
CVE-2021-34551LOWCVSS 8.12021
CVE-2021-34551 [HIGH] CVE-2021-34551: libphp-phpmailer - PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is u... PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2020-36326HIGHCVSS 8.8fixed in libphp-phpmailer 6.2.0-2 (bookworm)2020
CVE-2020-36326 [HIGH] CVE-2020-36326: libphp-phpmailer - PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserializati... PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminate
debian
CVE-2020-13625HIGHCVSS 7.5fixed in libphp-phpmailer 6.1.6-1 (bookworm)2020
CVE-2020-13625 [HIGH] CVE-2020-13625: libphp-phpmailer - PHPMailer before 6.1.6 contains an output escaping bug when the name of a file a... PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message. Scope: local bookworm: resolved (fixed in 6.1.6-1) bullseye: resolved (fixed in 6.1.6-1) forky: resolved (fixed in 6.1.6-1
debian
CVE-2018-19296HIGHCVSS 8.8fixed in libphp-phpmailer 5.2.14+dfsg-2.4 (bookworm)2018
CVE-2018-19296 [HIGH] CVE-2018-19296: libphp-phpmailer - PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injectio... PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. Scope: local bookworm: resolved (fixed in 5.2.14+dfsg-2.4) bullseye: resolved (fixed in 5.2.14+dfsg-2.4) forky: resolved (fixed in 5.2.14+dfsg-2.4) sid: resolved (fixed in 5.2.14+dfsg-2.4) trixie: resolved (fixed in 5.2.14+dfsg-2.4)
debian
CVE-2017-5223MEDIUMCVSS 5.5PoCfixed in libphp-phpmailer 5.2.14+dfsg-2.3 (bookworm)2017
CVE-2017-5223 [MEDIUM] CVE-2017-5223: libphp-phpmailer - An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method a... An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative image URLs into attachments using a script-provided base directory. If no base directory is provided, it resolves to /, meaning that relative
debian
CVE-2017-11503LOWCVSS 6.1fixed in libphp-phpmailer 6.0.6-0.1 (bookworm)2017
CVE-2017-11503 [MEDIUM] CVE-2017-11503: libphp-phpmailer - PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fiel... PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php. Scope: local bookworm: resolved (fixed in 6.0.6-0.1) bullseye: resolved (fixed in 6.0.6-0.1) forky: resolved (fixed in 6.0.6-0.1) sid: resolved (fixed in 6.0.6-0.1) trixie: resolved (fixed in 6.0.6-0.1)
debian
CVE-2016-10033CRITICALCVSS 9.8KEVPoCfixed in libphp-phpmailer 5.2.14+dfsg-2.1 (bookworm)2016
CVE-2016-10033 [CRITICAL] CVE-2016-10033: libphp-phpmailer - The mailSend function in the isMail transport in PHPMailer before 5.2.18 might a... The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property. Scope: local bookworm: resolved (fixed in 5.2.14+dfsg-2.1) bullseye: resolved (fixed in 5.2.14+dfsg-2.1)
debian
CVE-2016-10045LOWCVSS 9.8PoC2016
CVE-2016-10045 [CRITICAL] CVE-2016-10045: libphp-phpmailer - The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to ... The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix f
debian
CVE-2015-8476MEDIUMCVSS 4.0fixed in libphp-phpmailer 5.2.14+dfsg-1 (bookworm)2015
CVE-2015-8476 [MEDIUM] CVE-2015-8476: libphp-phpmailer - Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attacke... Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796. Scope: local bookworm: resolved
debian
CVE-2007-3215HIGHCVSS 6.8fixed in libphp-phpmailer 1.73-4 (bookworm)2007
CVE-2007-3215 [MEDIUM] CVE-2007-3215: libphp-phpmailer - PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execu... PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php. Scope: local bookworm: resolved (fixed in 1.73-4) bullseye: resolved (fixed in 1.73-4) forky: resolved (fixed in 1.73-4) sid: resolved (fixed in 1.73-4) trixie: resolved (fi
debian
CVE-2005-1807MEDIUMCVSS 5.0PoCfixed in libphp-phpmailer 1.73 (bookworm)2005
CVE-2005-1807 [MEDIUM] CVE-2005-1807: libphp-phpmailer - The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote... The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a long header field. Scope: local bookworm: resolved (fixed in 1.73) bullseye: resolved (fixed in 1.73) forky: resolved (fixed in 1.73) sid: resolved (fixed in 1.73) trixie: resolve
debian