Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2021-37746

Disclosure Date: July 30, 2021 (last updated November 08, 2023)
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
Attacker Value
Unknown

CVE-2020-16094

Disclosure Date: July 28, 2020 (last updated November 08, 2023)
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
Attacker Value
Unknown

CVE-2020-15917

Disclosure Date: July 23, 2020 (last updated November 08, 2023)
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
Attacker Value
Unknown

CVE-2015-8708

Disclosure Date: April 11, 2016 (last updated November 25, 2024)
Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8614.
0
Attacker Value
Unknown

CVE-2015-8614

Disclosure Date: April 11, 2016 (last updated November 08, 2023)
Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.
0
Attacker Value
Unknown

CVE-2014-2576

Disclosure Date: October 15, 2014 (last updated October 05, 2023)
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
0
Attacker Value
Unknown

CVE-2012-4507

Disclosure Date: October 22, 2012 (last updated October 05, 2023)
The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted email.
0
Attacker Value
Unknown

CVE-2007-6208

Disclosure Date: December 04, 2007 (last updated October 04, 2023)
sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.
0