Show filters
36 Total Results
Displaying 21-30 of 36
Sort by:
Attacker Value
Unknown
CVE-2006-5974
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger a NULL pointer dereference when calling the (1) ferror or (2) fflush functions.
0
Attacker Value
Unknown
CVE-2006-0321
Disclosure Date: January 24, 2006 (last updated February 22, 2025)
fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a free of an invalid pointer when fetchmail bounces the message to the originator or local postmaster.
0
Attacker Value
Unknown
CVE-2005-4348
Disclosure Date: December 21, 2005 (last updated February 22, 2025)
fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application crash) by sending messages without headers from upstream mail servers.
0
Attacker Value
Unknown
CVE-2005-3088
Disclosure Date: October 27, 2005 (last updated February 22, 2025)
fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which allows local users to obtain sensitive information such as passwords.
0
Attacker Value
Unknown
CVE-2005-2335
Disclosure Date: July 27, 2005 (last updated February 22, 2025)
Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses. NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.
0
Attacker Value
Unknown
CVE-2004-1053
Disclosure Date: March 01, 2005 (last updated February 22, 2025)
Integer overflow in fetch on FreeBSD 4.1 through 5.3 allows remote malicious servers to execute arbitrary code via certain HTTP headers in an HTTP response, which lead to a buffer overflow.
0
Attacker Value
Unknown
CVE-2003-1262
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Buffer overflow in the http_fetch function of HTTP Fetcher 1.0.0 and 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request via a long (1) host, (2) referer, or (3) userAgent value.
0
Attacker Value
Unknown
CVE-2003-0792
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.
0
Attacker Value
Unknown
CVE-2002-1365
Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header with a large number of local addresses.
0
Attacker Value
Unknown
CVE-2002-1175
Disclosure Date: October 11, 2002 (last updated February 22, 2025)
The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to read data beyond the expected boundary.
0