Skip to content
Noroxi

getmail records

5 published records for vendor getmail.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    Attack profile

    All records

    5 records
    • CVE-2014-7273
      27Monitor

      The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-th

      MediumCVSS 6.8No exploitEPSS 1%

      getmail · getmailOct 7, 2014

    • CVE-2014-7274
      23Monitor

      The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the subject's Common Na

      MediumCVSS 5.8No exploitEPSS 1%

      getmail · getmailOct 7, 2014

    • CVE-2014-7275
      23Monitor

      The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-th

      MediumCVSS 5.8No exploitEPSS 1%

      getmail · getmailOct 7, 2014

    • getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via

      LowCVSS 2.1No exploitEPSS 0%

      getmail · getmailJan 27, 2005

    • getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.

      LowCVSS 1.2No exploitEPSS 0%

      getmail · getmailJan 27, 2005