fetchmail records
24 published records for vendor fetchmail.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 79.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-399 Resource Management Errors3
- CWE-310 Cryptographic Issues1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2001-1009Proof of concept | Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory afetchmail · fetchmail · CWE-264 | Critical10.0 | — | 6.5% | Aug 31, 2001 |
41Plan | CVE-2001-0101No exploit | Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.fetchmail · fetchmail | Critical10.0 | — | 1.8% | Feb 12, 2001 |
32Monitor | CVE-2001-0819No exploit | A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email headfetchmail · fetchmail · CWE-119 | High7.5 | — | 6.4% | Dec 6, 2001 |
32Monitor | CVE-2006-5867No exploit | fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances fetchmail · fetchmail · CWE-20 | High7.8 | — | 4.4% | Dec 31, 2006 |
32Monitor | CVE-2006-5974No exploit | fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial fetchmail · fetchmail · CWE-20 | High7.8 | — | 3.9% | Dec 31, 2006 |
32Monitor | CVE-2005-4348No exploit | fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (applicafetchmail · fetchmail · CWE-399 | High7.8 | — | 3.6% | Dec 20, 2005 |
31Monitor | CVE-2002-1365No exploit | Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local afetchmail · fetchmail · CWE-119 | High7.5 | — | 5.0% | Dec 23, 2002 |
31Monitor | CVE-2002-1174No exploit | Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1fetchmail · fetchmail · CWE-119 | High7.5 | — | 4.7% | Oct 11, 2002 |
31Monitor | CVE-2021-36386No exploit | report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow maifetchmail · fetchmail · CWE-909 | High7.5 | — | 2.6% | Jul 30, 2021 |
28Monitor | CVE-2010-0562No exploit | The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, afetchmail · fetchmail · CWE-119 | Medium6.8 | — | 2.5% | Feb 8, 2010 |
25Monitor | CVE-2009-2666No exploit | socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of anfetchmail · fetchmail · CWE-310 | Medium6.4 | — | 1.5% | Aug 7, 2009 |
24Monitor | CVE-2012-3482No exploit | Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (cfetchmail · fetchmail | Medium5.8 | — | 1.9% | Dec 21, 2012 |
23Monitor | CVE-2021-39272No exploit | Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTfetchmail · fetchmail · CWE-319 | Medium5.9 | — | 0.9% | Aug 30, 2021 |
22Monitor | CVE-2005-2335No exploit | Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute fetchmail · fetchmail · CWE-119 | Medium5.0 | — | 5.9% | Jul 27, 2005 |
21Monitor | CVE-2006-0321No exploit | fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages thafetchmail · fetchmail · CWE-20 | Medium5.0 | — | 3.5% | Jan 23, 2006 |
21Monitor | CVE-2011-1947No exploit | fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote sfetchmail · fetchmail · CWE-399 | Medium5.0 | — | 2.6% | Jun 2, 2011 |
21Monitor | CVE-2003-0792No exploit | Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crfetchmail · fetchmail · CWE-399 | Medium5.0 | — | 2.0% | Nov 17, 2003 |
21Monitor | CVE-2002-1175No exploit | The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malfetchmail · fetchmail · CWE-20 | Medium5.0 | — | 2.0% | Oct 11, 2002 |
21Monitor | CVE-2007-4565No exploit | sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) byfetchmail · fetchmail | Medium5.0 | — | 2.0% | Aug 27, 2007 |
20Monitor | CVE-2002-0146No exploit | fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to fetchmail · fetchmail · CWE-20 | Medium5.0 | — | 1.5% | Jun 25, 2002 |
18Monitor | CVE-2008-2711No exploit | fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persifetchmail · fetchmail · CWE-20 | Medium4.3 | — | 3.0% | Jun 16, 2008 |
18Monitor | CVE-2010-1167No exploit | fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which afetchmail · fetchmail · CWE-20 | Medium4.3 | — | 2.2% | May 7, 2010 |
8Monitor | CVE-2005-3088No exploit | fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which fetchmail · fetchmail · CWE-200 | Low2.1 | — | 0.5% | Oct 27, 2005 |
8Monitor | CVE-2001-1378No exploit | fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.fetchmail · fetchmail · CWE-59 | Low2.1 | — | 0.3% | Sep 6, 2001 |
- CVE-2001-100942Plan
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory a
CriticalCVSS 10.0Proof of conceptEPSS 7%fetchmail · fetchmailAug 31, 2001
- CVE-2001-010141Plan
Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.
CriticalCVSS 10.0No exploitEPSS 2%fetchmail · fetchmailFeb 12, 2001
- CVE-2001-081932Monitor
A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email head
HighCVSS 7.5No exploitEPSS 6%fetchmail · fetchmailDec 6, 2001
- CVE-2006-586732Monitor
fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances
HighCVSS 7.8No exploitEPSS 4%fetchmail · fetchmailDec 31, 2006
- CVE-2006-597432Monitor
fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial
HighCVSS 7.8No exploitEPSS 4%fetchmail · fetchmailDec 31, 2006
- CVE-2005-434832Monitor
fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (applica
HighCVSS 7.8No exploitEPSS 4%fetchmail · fetchmailDec 20, 2005
- CVE-2002-136531Monitor
Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local a
HighCVSS 7.5No exploitEPSS 5%fetchmail · fetchmailDec 23, 2002
- CVE-2002-117431Monitor
Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1
HighCVSS 7.5No exploitEPSS 5%fetchmail · fetchmailOct 11, 2002
- CVE-2021-3638631Monitor
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mai
HighCVSS 7.5No exploitEPSS 3%fetchmail · fetchmailJul 30, 2021
- CVE-2010-056228Monitor
The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, a
MediumCVSS 6.8No exploitEPSS 2%fetchmail · fetchmailFeb 8, 2010
- CVE-2009-266625Monitor
socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an
MediumCVSS 6.4No exploitEPSS 2%fetchmail · fetchmailAug 7, 2009
- CVE-2012-348224Monitor
Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (c
MediumCVSS 5.8No exploitEPSS 2%fetchmail · fetchmailDec 21, 2012
- CVE-2021-3927223Monitor
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUT
MediumCVSS 5.9No exploitEPSS 1%fetchmail · fetchmailAug 30, 2021
- CVE-2005-233522Monitor
Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute
MediumCVSS 5.0No exploitEPSS 6%fetchmail · fetchmailJul 27, 2005
- CVE-2006-032121Monitor
fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages tha
MediumCVSS 5.0No exploitEPSS 4%fetchmail · fetchmailJan 23, 2006
- CVE-2011-194721Monitor
fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote s
MediumCVSS 5.0No exploitEPSS 3%fetchmail · fetchmailJun 2, 2011
- CVE-2003-079221Monitor
Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (cr
MediumCVSS 5.0No exploitEPSS 2%fetchmail · fetchmailNov 17, 2003
- CVE-2002-117521Monitor
The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a mal
MediumCVSS 5.0No exploitEPSS 2%fetchmail · fetchmailOct 11, 2002
- CVE-2007-456521Monitor
sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) by
MediumCVSS 5.0No exploitEPSS 2%fetchmail · fetchmailAug 27, 2007
- CVE-2002-014620Monitor
fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to
MediumCVSS 5.0No exploitEPSS 1%fetchmail · fetchmailJun 25, 2002
- CVE-2008-271118Monitor
fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persi
MediumCVSS 4.3No exploitEPSS 3%fetchmail · fetchmailJun 16, 2008
- CVE-2010-116718Monitor
fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which a
MediumCVSS 4.3No exploitEPSS 2%fetchmail · fetchmailMay 7, 2010
- CVE-2005-30888Monitor
fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which
LowCVSS 2.1No exploitEPSS 0%fetchmail · fetchmailOct 27, 2005
- CVE-2001-13788Monitor
fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.
LowCVSS 2.1No exploitEPSS 0%fetchmail · fetchmailSep 6, 2001