Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2014-7273

Disclosure Date: October 08, 2014 (last updated October 05, 2023)
The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7275

Disclosure Date: October 08, 2014 (last updated October 05, 2023)
The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof POP3 servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2004-0880

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.
0
Attacker Value
Unknown

CVE-2004-0881

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.
0