Записи fetchmail
24 опубликованных записей вендора fetchmail.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 79,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-399 Resource Management Errors3
- CWE-310 Cryptographic Issues1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2001-1009Proof of concept | Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory afetchmail · fetchmail · CWE-264 | Критическая10,0 | — | 6,5 % | 31 авг. 2001 г. |
41В плане | CVE-2001-0101Эксплойта нет | Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.fetchmail · fetchmail | Критическая10,0 | — | 1,8 % | 12 февр. 2001 г. |
32Наблюдать | CVE-2001-0819Эксплойта нет | A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email headfetchmail · fetchmail · CWE-119 | Высокая7,5 | — | 6,4 % | 6 дек. 2001 г. |
32Наблюдать | CVE-2006-5867Эксплойта нет | fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances fetchmail · fetchmail · CWE-20 | Высокая7,8 | — | 4,4 % | 31 дек. 2006 г. |
32Наблюдать | CVE-2006-5974Эксплойта нет | fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial fetchmail · fetchmail · CWE-20 | Высокая7,8 | — | 3,9 % | 31 дек. 2006 г. |
32Наблюдать | CVE-2005-4348Эксплойта нет | fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (applicafetchmail · fetchmail · CWE-399 | Высокая7,8 | — | 3,6 % | 20 дек. 2005 г. |
31Наблюдать | CVE-2002-1365Эксплойта нет | Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local afetchmail · fetchmail · CWE-119 | Высокая7,5 | — | 5,0 % | 23 дек. 2002 г. |
31Наблюдать | CVE-2002-1174Эксплойта нет | Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1fetchmail · fetchmail · CWE-119 | Высокая7,5 | — | 4,7 % | 11 окт. 2002 г. |
31Наблюдать | CVE-2021-36386Эксплойта нет | report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow maifetchmail · fetchmail · CWE-909 | Высокая7,5 | — | 2,6 % | 30 июл. 2021 г. |
28Наблюдать | CVE-2010-0562Эксплойта нет | The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, afetchmail · fetchmail · CWE-119 | Средняя6,8 | — | 2,5 % | 8 февр. 2010 г. |
25Наблюдать | CVE-2009-2666Эксплойта нет | socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of anfetchmail · fetchmail · CWE-310 | Средняя6,4 | — | 1,5 % | 7 авг. 2009 г. |
24Наблюдать | CVE-2012-3482Эксплойта нет | Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (cfetchmail · fetchmail | Средняя5,8 | — | 1,9 % | 21 дек. 2012 г. |
23Наблюдать | CVE-2021-39272Эксплойта нет | Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTfetchmail · fetchmail · CWE-319 | Средняя5,9 | — | 0,9 % | 30 авг. 2021 г. |
22Наблюдать | CVE-2005-2335Эксплойта нет | Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute fetchmail · fetchmail · CWE-119 | Средняя5,0 | — | 5,9 % | 27 июл. 2005 г. |
21Наблюдать | CVE-2006-0321Эксплойта нет | fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages thafetchmail · fetchmail · CWE-20 | Средняя5,0 | — | 3,5 % | 23 янв. 2006 г. |
21Наблюдать | CVE-2011-1947Эксплойта нет | fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote sfetchmail · fetchmail · CWE-399 | Средняя5,0 | — | 2,6 % | 2 июн. 2011 г. |
21Наблюдать | CVE-2003-0792Эксплойта нет | Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crfetchmail · fetchmail · CWE-399 | Средняя5,0 | — | 2,0 % | 17 нояб. 2003 г. |
21Наблюдать | CVE-2002-1175Эксплойта нет | The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malfetchmail · fetchmail · CWE-20 | Средняя5,0 | — | 2,0 % | 11 окт. 2002 г. |
21Наблюдать | CVE-2007-4565Эксплойта нет | sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) byfetchmail · fetchmail | Средняя5,0 | — | 2,0 % | 27 авг. 2007 г. |
20Наблюдать | CVE-2002-0146Эксплойта нет | fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to fetchmail · fetchmail · CWE-20 | Средняя5,0 | — | 1,5 % | 25 июн. 2002 г. |
18Наблюдать | CVE-2008-2711Эксплойта нет | fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persifetchmail · fetchmail · CWE-20 | Средняя4,3 | — | 3,0 % | 16 июн. 2008 г. |
18Наблюдать | CVE-2010-1167Эксплойта нет | fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which afetchmail · fetchmail · CWE-20 | Средняя4,3 | — | 2,2 % | 7 мая 2010 г. |
8Наблюдать | CVE-2005-3088Эксплойта нет | fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which fetchmail · fetchmail · CWE-200 | Низкая2,1 | — | 0,5 % | 27 окт. 2005 г. |
8Наблюдать | CVE-2001-1378Эксплойта нет | fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.fetchmail · fetchmail · CWE-59 | Низкая2,1 | — | 0,3 % | 6 сент. 2001 г. |
- CVE-2001-100942В плане
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory a
КритическаяCVSS 10,0Proof of conceptEPSS 7 %fetchmail · fetchmail31 авг. 2001 г.
- CVE-2001-010141В плане
Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %fetchmail · fetchmail12 февр. 2001 г.
- CVE-2001-081932Наблюдать
A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email head
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %fetchmail · fetchmail6 дек. 2001 г.
- CVE-2006-586732Наблюдать
fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances
ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %fetchmail · fetchmail31 дек. 2006 г.
- CVE-2006-597432Наблюдать
fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial
ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %fetchmail · fetchmail31 дек. 2006 г.
- CVE-2005-434832Наблюдать
fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (applica
ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %fetchmail · fetchmail20 дек. 2005 г.
- CVE-2002-136531Наблюдать
Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local a
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %fetchmail · fetchmail23 дек. 2002 г.
- CVE-2002-117431Наблюдать
Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %fetchmail · fetchmail11 окт. 2002 г.
- CVE-2021-3638631Наблюдать
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mai
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %fetchmail · fetchmail30 июл. 2021 г.
- CVE-2010-056228Наблюдать
The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, a
СредняяCVSS 6,8Эксплойта нетEPSS 2 %fetchmail · fetchmail8 февр. 2010 г.
- CVE-2009-266625Наблюдать
socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an
СредняяCVSS 6,4Эксплойта нетEPSS 2 %fetchmail · fetchmail7 авг. 2009 г.
- CVE-2012-348224Наблюдать
Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (c
СредняяCVSS 5,8Эксплойта нетEPSS 2 %fetchmail · fetchmail21 дек. 2012 г.
- CVE-2021-3927223Наблюдать
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUT
СредняяCVSS 5,9Эксплойта нетEPSS 1 %fetchmail · fetchmail30 авг. 2021 г.
- CVE-2005-233522Наблюдать
Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute
СредняяCVSS 5,0Эксплойта нетEPSS 6 %fetchmail · fetchmail27 июл. 2005 г.
- CVE-2006-032121Наблюдать
fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages tha
СредняяCVSS 5,0Эксплойта нетEPSS 4 %fetchmail · fetchmail23 янв. 2006 г.
- CVE-2011-194721Наблюдать
fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote s
СредняяCVSS 5,0Эксплойта нетEPSS 3 %fetchmail · fetchmail2 июн. 2011 г.
- CVE-2003-079221Наблюдать
Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (cr
СредняяCVSS 5,0Эксплойта нетEPSS 2 %fetchmail · fetchmail17 нояб. 2003 г.
- CVE-2002-117521Наблюдать
The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a mal
СредняяCVSS 5,0Эксплойта нетEPSS 2 %fetchmail · fetchmail11 окт. 2002 г.
- CVE-2007-456521Наблюдать
sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) by
СредняяCVSS 5,0Эксплойта нетEPSS 2 %fetchmail · fetchmail27 авг. 2007 г.
- CVE-2002-014620Наблюдать
fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to
СредняяCVSS 5,0Эксплойта нетEPSS 1 %fetchmail · fetchmail25 июн. 2002 г.
- CVE-2008-271118Наблюдать
fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persi
СредняяCVSS 4,3Эксплойта нетEPSS 3 %fetchmail · fetchmail16 июн. 2008 г.
- CVE-2010-116718Наблюдать
fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which a
СредняяCVSS 4,3Эксплойта нетEPSS 2 %fetchmail · fetchmail7 мая 2010 г.
- CVE-2005-30888Наблюдать
fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %fetchmail · fetchmail27 окт. 2005 г.
- CVE-2001-13788Наблюдать
fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %fetchmail · fetchmail6 сент. 2001 г.