mutt records
46 published records for vendor mutt.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 10
- With a fix record
- 76.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-787 Out-of-bounds Write3
- CWE-475 Undefined Behavior for Input to API2
- CWE-310 Cryptographic Issues2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
46 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2018-14354No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-78 | Critical9.8 | — | 6.2% | Jul 17, 2018 |
40Plan | CVE-2018-14350No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-787 | Critical9.8 | — | 5.0% | Jul 17, 2018 |
40Plan | CVE-2018-14357No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-78 | Critical9.8 | — | 5.0% | Jul 17, 2018 |
40Plan | CVE-2018-14359No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-120 | Critical9.8 | — | 4.1% | Jul 17, 2018 |
40Plan | CVE-2018-14352No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-787 | Critical9.8 | — | 4.0% | Jul 17, 2018 |
40Plan | CVE-2018-14358No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-787 | Critical9.8 | — | 3.9% | Jul 17, 2018 |
40Plan | CVE-2018-14353No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-191 | Critical9.8 | — | 3.7% | Jul 17, 2018 |
40Plan | CVE-2018-14362No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-119 | Critical9.8 | — | 3.7% | Jul 17, 2018 |
40Plan | CVE-2018-14349No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-20 | Critical9.8 | — | 3.2% | Jul 17, 2018 |
40Plan | CVE-2018-14356No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-824 | Critical9.8 | — | 3.2% | Jul 17, 2018 |
40Plan | CVE-2018-14351No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-20 | Critical9.8 | — | 3.2% | Jul 17, 2018 |
37Monitor | CVE-2021-32055No exploit | Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an outmutt · mutt · CWE-125 | Critical9.1 | — | 2.6% | May 5, 2021 |
32Monitor | CVE-2006-3242No exploit | Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to caumutt · mutt | High7.5 | — | 6.0% | Jun 27, 2006 |
32Monitor | CVE-2004-0078No exploit | Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of smutt · mutt | High7.5 | — | 5.4% | Mar 3, 2004 |
31Monitor | CVE-2003-0140No exploit | Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2mutt · mutt | High7.5 | — | 4.5% | Mar 24, 2003 |
31Monitor | CVE-2005-2642No exploit | Buffer overflow in the mutt_decode_xbit function in Handler.c for Mutt 1.5.10 allows remote attackers to execute arbitrary code, possibly dumutt · mutt | High7.5 | — | 4.5% | Aug 23, 2005 |
31Monitor | CVE-2002-0001No exploit | Vulnerability in RFC822 address parser in mutt before 1.2.5.1 and mutt 1.3.x before 1.3.25 allows remote attackers to execute arbitrary commmutt · mutt | High7.5 | — | 3.4% | Feb 27, 2002 |
31Monitor | CVE-1999-0940No exploit | Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.mutt · mutt mail client | High7.5 | — | 2.7% | Sep 27, 1999 |
31Monitor | CVE-2003-0167No exploit | Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote maliciomutt · mutt | High7.5 | — | 2.5% | Apr 2, 2003 |
31Monitor | CVE-2003-0299No exploit | The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly execmutt · mutt | High7.5 | — | 2.1% | Jun 16, 2003 |
31Monitor | CVE-2001-0473No exploit | Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.mutt · mutt | High7.5 | — | 2.1% | Jun 27, 2001 |
31Monitor | CVE-1999-0941No exploit | Mutt mail client allows a remote attacker to execute commands via shell metacharacters.mutt · mutt | High7.5 | — | 1.8% | Jul 28, 1998 |
28Monitor | CVE-2009-1390No exploit | Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificatmutt · mutt · CWE-287 | Medium6.8 | — | 1.9% | Jun 16, 2009 |
27Monitor | CVE-2021-3181No exploit | rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with mutt · mutt · CWE-401 | Medium6.5 | — | 2.8% | Jan 19, 2021 |
27Monitor | CVE-2009-3766No exploit | mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Namutt · mutt · CWE-310 | Medium6.8 | — | 1.1% | Oct 23, 2009 |
- CVE-2018-1435441Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 6%mutt · muttJul 17, 2018
- CVE-2018-1435040Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 5%mutt · muttJul 17, 2018
- CVE-2018-1435740Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 5%mutt · muttJul 17, 2018
- CVE-2018-1435940Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 4%mutt · muttJul 17, 2018
- CVE-2018-1435240Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 4%mutt · muttJul 17, 2018
- CVE-2018-1435840Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 4%mutt · muttJul 17, 2018
- CVE-2018-1435340Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 4%mutt · muttJul 17, 2018
- CVE-2018-1436240Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 4%mutt · muttJul 17, 2018
- CVE-2018-1434940Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 3%mutt · muttJul 17, 2018
- CVE-2018-1435640Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 3%mutt · muttJul 17, 2018
- CVE-2018-1435140Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 3%mutt · muttJul 17, 2018
- CVE-2021-3205537Monitor
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out
CriticalCVSS 9.1No exploitEPSS 3%mutt · muttMay 5, 2021
- CVE-2006-324232Monitor
Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cau
HighCVSS 7.5No exploitEPSS 6%mutt · muttJun 27, 2006
- CVE-2004-007832Monitor
Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of s
HighCVSS 7.5No exploitEPSS 5%mutt · muttMar 3, 2004
- CVE-2003-014031Monitor
Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2
HighCVSS 7.5No exploitEPSS 4%mutt · muttMar 24, 2003
- CVE-2005-264231Monitor
Buffer overflow in the mutt_decode_xbit function in Handler.c for Mutt 1.5.10 allows remote attackers to execute arbitrary code, possibly du
HighCVSS 7.5No exploitEPSS 4%mutt · muttAug 23, 2005
- CVE-2002-000131Monitor
Vulnerability in RFC822 address parser in mutt before 1.2.5.1 and mutt 1.3.x before 1.3.25 allows remote attackers to execute arbitrary comm
HighCVSS 7.5No exploitEPSS 3%mutt · muttFeb 27, 2002
- CVE-1999-094031Monitor
Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.
HighCVSS 7.5No exploitEPSS 3%mutt · mutt mail clientSep 27, 1999
- CVE-2003-016731Monitor
Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicio
HighCVSS 7.5No exploitEPSS 3%mutt · muttApr 2, 2003
- CVE-2003-029931Monitor
The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly exec
HighCVSS 7.5No exploitEPSS 2%mutt · muttJun 16, 2003
- CVE-2001-047331Monitor
Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.
HighCVSS 7.5No exploitEPSS 2%mutt · muttJun 27, 2001
- CVE-1999-094131Monitor
Mutt mail client allows a remote attacker to execute commands via shell metacharacters.
HighCVSS 7.5No exploitEPSS 2%mutt · muttJul 28, 1998
- CVE-2009-139028Monitor
Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificat
MediumCVSS 6.8No exploitEPSS 2%mutt · muttJun 16, 2009
- CVE-2021-318127Monitor
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with
MediumCVSS 6.5No exploitEPSS 3%mutt · muttJan 19, 2021
- CVE-2009-376627Monitor
mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Na
MediumCVSS 6.8No exploitEPSS 1%mutt · muttOct 23, 2009