getmail records
5 published records for vendor getmail.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
27Monitor | CVE-2014-7273No exploit | The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-thgetmail · getmail · CWE-310 | Medium6.8 | — | 0.9% | Oct 7, 2014 |
23Monitor | CVE-2014-7274No exploit | The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the subject's Common Nagetmail · getmail · CWE-310 | Medium5.8 | — | 0.8% | Oct 7, 2014 |
23Monitor | CVE-2014-7275No exploit | The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-thgetmail · getmail · CWE-310 | Medium5.8 | — | 0.8% | Oct 7, 2014 |
8Monitor | CVE-2004-0881No exploit | getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via getmail · getmail | Low2.1 | — | 0.4% | Jan 27, 2005 |
4Monitor | CVE-2004-0880No exploit | getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.getmail · getmail | Low1.2 | — | 0.3% | Jan 27, 2005 |
- CVE-2014-727327Monitor
The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-th
MediumCVSS 6.8No exploitEPSS 1%getmail · getmailOct 7, 2014
- CVE-2014-727423Monitor
The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the subject's Common Na
MediumCVSS 5.8No exploitEPSS 1%getmail · getmailOct 7, 2014
- CVE-2014-727523Monitor
The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-th
MediumCVSS 5.8No exploitEPSS 1%getmail · getmailOct 7, 2014
- CVE-2004-08818Monitor
getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via
LowCVSS 2.1No exploitEPSS 0%getmail · getmailJan 27, 2005
- CVE-2004-08804Monitor
getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.
LowCVSS 1.2No exploitEPSS 0%getmail · getmailJan 27, 2005