cbcvebase.

Debian Mutt vulnerabilities

39 known vulnerabilities affecting debian/mutt.

Total CVEs
39
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH4MEDIUM10LOW11

Vulnerabilities

Page 1 of 2
CVE-2018-14354P2CRITICALCVSS 9.8fixed in mutt 1.10.1-1 (bookworm)2018
CVE-2018-14354 [CRITICAL] CVE-2018-14354: mutt - An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. The... An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed
debian
CVE-2018-14357P2CRITICALCVSS 9.8fixed in mutt 1.10.1-1 (bookworm)2018
CVE-2018-14357 [CRITICAL] CVE-2018-14357: mutt - An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. The... An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.10.1-1)
debian
CVE-2018-14350P3CRITICALCVSS 9.8fixed in mutt 1.10.1-1 (bookworm)2018
CVE-2018-14350 [CRITICAL] CVE-2018-14350: mutt - An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. ima... An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long INTERNALDATE field. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.10.1-1) sid: resolved (fixed in 1.10.1-1) trixie: resolved (fixed in
debian
CVE-2018-14359P3CRITICALCVSS 9.8fixed in mutt 1.10.1-1 (bookworm)2018
CVE-2018-14359 [CRITICAL] CVE-2018-14359: mutt - An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. The... An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.10.1-1) sid: resolved (fixed in 1.10.1-1) trixie: resolved (fixed in 1.10.1-1)
debian
CVE-2018-14352P3CRITICALCVSS 9.8fixed in mutt 1.10.1-1 (bookworm)2018
CVE-2018-14352 [CRITICAL] CVE-2018-14352: mutt - An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. ima... An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.10.1-1) sid: resolved (fixed in 1.10.1-1) trixie: reso
debian
CVE-2018-14358P3CRITICALCVSS 9.8fixed in mutt 1.10.1-1 (bookworm)2018
CVE-2018-14358 [CRITICAL] CVE-2018-14358: mutt - An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. ima... An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.10.1-1) sid: resolved (fixed in 1.10.1-1) trixie: resolved (fixed in 1
debian
CVE-2018-14349P3CRITICALCVSS 9.8fixed in mutt 1.10.1-1 (bookworm)2018
CVE-2018-14349 [CRITICAL] CVE-2018-14349: mutt - An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. ima... An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.10.1-1) sid: resolved (fixed in 1.10.1-1) trixie: resolved (fixed in 1.10.1-1)
debian
CVE-2018-14360P3CRITICALCVSS 9.8fixed in mutt 1.9.1-1 (bookworm)2018
CVE-2018-14360 [CRITICAL] CVE-2018-14360: mutt - An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c... An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage. Scope: local bookworm: resolved (fixed in 1.9.1-1) bullseye: resolved (fixed in 1.9.1-1) forky: resolved (fixed in 1.9.1-1) sid: resolved (fixed in 1.9.1-1) trixie: resolved (fixed in 1.9.1-1)
debian
CVE-2018-14353P3CRITICALCVSS 9.8fixed in mutt 1.10.1-1 (bookworm)2018
CVE-2018-14353 [CRITICAL] CVE-2018-14353: mutt - An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. ima... An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.10.1-1) sid: resolved (fixed in 1.10.1-1) trixie: resolved (fixed in 1.10.1-1)
debian
CVE-2018-14351P3CRITICALCVSS 9.8fixed in mutt 1.10.1-1 (bookworm)2018
CVE-2018-14351 [CRITICAL] CVE-2018-14351: mutt - An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. ima... An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.10.1-1) sid: resolved (fixed in 1.10.1-1) trixie: resolved (fixed in 1.10.1-1)
debian
CVE-2021-32055P3CRITICALCVSS 9.1fixed in mutt 2.0.5-4.1 (bookworm)2021
CVE-2021-32055 [CRITICAL] CVE-2021-32055: mutt - Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-0... Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default. Scope: local bookworm: resolved (fixed in 2.0.5-4.1) bullseye: resolved (fixed i
debian
CVE-2018-14362P3CRITICALCVSS 9.8fixed in mutt 1.10.1-1 (bookworm)2018
CVE-2018-14362 [CRITICAL] CVE-2018-14362: mutt - An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop... An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.10.1-1) sid: resolved (fixed in 1.10.1-
debian
CVE-2018-14356P3CRITICALCVSS 9.8fixed in mutt 1.10.1-1 (bookworm)2018
CVE-2018-14356 [CRITICAL] CVE-2018-14356: mutt - An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop... An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID. Scope: local bookworm: resolved (fixed in 1.10.1-1) bullseye: resolved (fixed in 1.10.1-1) forky: resolved (fixed in 1.10.1-1) sid: resolved (fixed in 1.10.1-1) trixie: resolved (fixed in 1.10.1-1)
debian
CVE-2018-14361P3CRITICALCVSS 9.8fixed in mutt 1.9.1-1 (bookworm)2018
CVE-2018-14361 [CRITICAL] CVE-2018-14361: mutt - An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if me... An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data. Scope: local bookworm: resolved (fixed in 1.9.1-1) bullseye: resolved (fixed in 1.9.1-1) forky: resolved (fixed in 1.9.1-1) sid: resolved (fixed in 1.9.1-1) trixie: resolved (fixed in 1.9.1-1)
debian
CVE-2006-3242P3LOWCVSS 7.5fixed in mutt 1.5.11+cvs20060403-2 (bookworm)2006
CVE-2006-3242 [HIGH] CVE-2006-3242: mutt - Stack-based buffer overflow in the browse_get_namespace function in imap/browse.... Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server. Scope: local bookworm: resolved (fixed in 1.5.11+cvs20060403-2) bullseye: resolved (fixed in 1.5.11+cvs20060403-2) forky: res
debian
CVE-2007-2683P4LOWCVSS 3.5PoCfixed in mutt 1.5.15+20070608-1 (bookworm)2007
CVE-2007-2683 [LOW] CVE-2007-2683: mutt - Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code ... Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion. Scope: local bookworm: resolved (fixed in 1.5.15+20070608-1) bullseye: resolved (fixed in 1.5.15+20070608-1) forky: resolved (fixed in 1.5.15+20070608-1) sid: resolved (fixed in 1.5.15+20070608-1) trixie
debian
CVE-2018-14363P3HIGHCVSS 7.5fixed in mutt 1.9.1-1 (bookworm)2018
CVE-2018-14363 [HIGH] CVE-2018-14363: mutt - An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly... An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames. Scope: local bookworm: resolved (fixed in 1.9.1-1) bullseye: resolved (fixed in 1.9.1-1) forky: resolved (fixed in 1.9.1-1) sid: resolved (fixed in 1.9.1-1) trixie: resolved (fixed in 1.9.1-1)
debian
CVE-2014-9116P4MEDIUMCVSS 5.0fixed in mutt 1.5.23-2 (bookworm)2014
CVE-2014-9116 [MEDIUM] CVE-2014-9116: mutt - The write_one_header function in mutt 1.5.23 does not properly handle newline ch... The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function. Scope: local bookworm: resolved (fixed in 1.5.23-2) bullseye: resolved (fixe
debian
CVE-2020-14954P4MEDIUMCVSS 5.9fixed in mutt 1.14.4-1 (bookworm)2020
CVE-2020-14954 [MEDIUM] CVE-2020-14954: mutt - Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue... Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection." Scope: local bookworm: resolved (fixed in 1.14.4-1) bullseye: resolved (f
debian
CVE-2004-0078P4HIGHCVSS 7.5fixed in mutt 1.5.6-20040722+1 (bookworm)2004
CVE-2004-0078 [HIGH] CVE-2004-0078: mutt - Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.... Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages. Scope: local bookworm: resolved (fixed in 1.5.6-20040722+1) bullseye: resolved (fixed in 1.5.6-20040722+1) forky: resolved (fixed in 1.5.6-20040722+1) sid:
debian
Debian Mutt vulnerabilities | cvebase