Skip to content
Noroxi

fetchmail records

24 published records for vendor fetchmail.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
79.2%
Median publish → KEV
No record has entered KEV

All records

24 records
  • Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory a

    CriticalCVSS 10.0Proof of conceptEPSS 7%

    fetchmail · fetchmailAug 31, 2001

  • Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.

    CriticalCVSS 10.0No exploitEPSS 2%

    fetchmail · fetchmailFeb 12, 2001

  • CVE-2001-0819
    32Monitor

    A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email head

    HighCVSS 7.5No exploitEPSS 6%

    fetchmail · fetchmailDec 6, 2001

  • CVE-2006-5867
    32Monitor

    fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances

    HighCVSS 7.8No exploitEPSS 4%

    fetchmail · fetchmailDec 31, 2006

  • CVE-2006-5974
    32Monitor

    fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial

    HighCVSS 7.8No exploitEPSS 4%

    fetchmail · fetchmailDec 31, 2006

  • CVE-2005-4348
    32Monitor

    fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (applica

    HighCVSS 7.8No exploitEPSS 4%

    fetchmail · fetchmailDec 20, 2005

  • CVE-2002-1365
    31Monitor

    Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local a

    HighCVSS 7.5No exploitEPSS 5%

    fetchmail · fetchmailDec 23, 2002

  • CVE-2002-1174
    31Monitor

    Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1

    HighCVSS 7.5No exploitEPSS 5%

    fetchmail · fetchmailOct 11, 2002

  • report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mai

    HighCVSS 7.5No exploitEPSS 3%

    fetchmail · fetchmailJul 30, 2021

  • CVE-2010-0562
    28Monitor

    The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, a

    MediumCVSS 6.8No exploitEPSS 2%

    fetchmail · fetchmailFeb 8, 2010

  • CVE-2009-2666
    25Monitor

    socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an

    MediumCVSS 6.4No exploitEPSS 2%

    fetchmail · fetchmailAug 7, 2009

  • CVE-2012-3482
    24Monitor

    Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (c

    MediumCVSS 5.8No exploitEPSS 2%

    fetchmail · fetchmailDec 21, 2012

  • Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUT

    MediumCVSS 5.9No exploitEPSS 1%

    fetchmail · fetchmailAug 30, 2021

  • CVE-2005-2335
    22Monitor

    Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute

    MediumCVSS 5.0No exploitEPSS 6%

    fetchmail · fetchmailJul 27, 2005

  • CVE-2006-0321
    21Monitor

    fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages tha

    MediumCVSS 5.0No exploitEPSS 4%

    fetchmail · fetchmailJan 23, 2006

  • CVE-2011-1947
    21Monitor

    fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote s

    MediumCVSS 5.0No exploitEPSS 3%

    fetchmail · fetchmailJun 2, 2011

  • CVE-2003-0792
    21Monitor

    Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (cr

    MediumCVSS 5.0No exploitEPSS 2%

    fetchmail · fetchmailNov 17, 2003

  • CVE-2002-1175
    21Monitor

    The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a mal

    MediumCVSS 5.0No exploitEPSS 2%

    fetchmail · fetchmailOct 11, 2002

  • CVE-2007-4565
    21Monitor

    sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) by

    MediumCVSS 5.0No exploitEPSS 2%

    fetchmail · fetchmailAug 27, 2007

  • CVE-2002-0146
    20Monitor

    fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to

    MediumCVSS 5.0No exploitEPSS 1%

    fetchmail · fetchmailJun 25, 2002

  • CVE-2008-2711
    18Monitor

    fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persi

    MediumCVSS 4.3No exploitEPSS 3%

    fetchmail · fetchmailJun 16, 2008

  • CVE-2010-1167
    18Monitor

    fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which a

    MediumCVSS 4.3No exploitEPSS 2%

    fetchmail · fetchmailMay 7, 2010

  • fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which

    LowCVSS 2.1No exploitEPSS 0%

    fetchmail · fetchmailOct 27, 2005

  • fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.

    LowCVSS 2.1No exploitEPSS 0%

    fetchmail · fetchmailSep 6, 2001