fetchmail kayıtları
fetchmail üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %79,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-399 Resource Management Errors3
- CWE-310 Cryptographic Issues1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2001-1009Kavram kanıtı | Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory afetchmail · fetchmail · CWE-264 | Kritik10,0 | — | %6,5 | 31 Ağu 2001 |
41Planlayın | CVE-2001-0101İstismar yok | Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.fetchmail · fetchmail | Kritik10,0 | — | %1,8 | 12 Şub 2001 |
32İzleyin | CVE-2001-0819İstismar yok | A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email headfetchmail · fetchmail · CWE-119 | Yüksek7,5 | — | %6,4 | 6 Ara 2001 |
32İzleyin | CVE-2006-5867İstismar yok | fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances fetchmail · fetchmail · CWE-20 | Yüksek7,8 | — | %4,4 | 31 Ara 2006 |
32İzleyin | CVE-2006-5974İstismar yok | fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial fetchmail · fetchmail · CWE-20 | Yüksek7,8 | — | %3,9 | 31 Ara 2006 |
32İzleyin | CVE-2005-4348İstismar yok | fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (applicafetchmail · fetchmail · CWE-399 | Yüksek7,8 | — | %3,6 | 20 Ara 2005 |
31İzleyin | CVE-2002-1365İstismar yok | Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local afetchmail · fetchmail · CWE-119 | Yüksek7,5 | — | %5,0 | 23 Ara 2002 |
31İzleyin | CVE-2002-1174İstismar yok | Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1fetchmail · fetchmail · CWE-119 | Yüksek7,5 | — | %4,7 | 11 Eki 2002 |
31İzleyin | CVE-2021-36386İstismar yok | report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow maifetchmail · fetchmail · CWE-909 | Yüksek7,5 | — | %2,6 | 30 Tem 2021 |
28İzleyin | CVE-2010-0562İstismar yok | The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, afetchmail · fetchmail · CWE-119 | Orta6,8 | — | %2,5 | 8 Şub 2010 |
25İzleyin | CVE-2009-2666İstismar yok | socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of anfetchmail · fetchmail · CWE-310 | Orta6,4 | — | %1,5 | 7 Ağu 2009 |
24İzleyin | CVE-2012-3482İstismar yok | Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (cfetchmail · fetchmail | Orta5,8 | — | %1,9 | 21 Ara 2012 |
23İzleyin | CVE-2021-39272İstismar yok | Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTfetchmail · fetchmail · CWE-319 | Orta5,9 | — | %0,9 | 30 Ağu 2021 |
22İzleyin | CVE-2005-2335İstismar yok | Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute fetchmail · fetchmail · CWE-119 | Orta5,0 | — | %5,9 | 27 Tem 2005 |
21İzleyin | CVE-2006-0321İstismar yok | fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages thafetchmail · fetchmail · CWE-20 | Orta5,0 | — | %3,5 | 23 Oca 2006 |
21İzleyin | CVE-2011-1947İstismar yok | fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote sfetchmail · fetchmail · CWE-399 | Orta5,0 | — | %2,6 | 2 Haz 2011 |
21İzleyin | CVE-2003-0792İstismar yok | Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crfetchmail · fetchmail · CWE-399 | Orta5,0 | — | %2,0 | 17 Kas 2003 |
21İzleyin | CVE-2002-1175İstismar yok | The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malfetchmail · fetchmail · CWE-20 | Orta5,0 | — | %2,0 | 11 Eki 2002 |
21İzleyin | CVE-2007-4565İstismar yok | sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) byfetchmail · fetchmail | Orta5,0 | — | %2,0 | 27 Ağu 2007 |
20İzleyin | CVE-2002-0146İstismar yok | fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to fetchmail · fetchmail · CWE-20 | Orta5,0 | — | %1,5 | 25 Haz 2002 |
18İzleyin | CVE-2008-2711İstismar yok | fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persifetchmail · fetchmail · CWE-20 | Orta4,3 | — | %3,0 | 16 Haz 2008 |
18İzleyin | CVE-2010-1167İstismar yok | fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which afetchmail · fetchmail · CWE-20 | Orta4,3 | — | %2,2 | 7 May 2010 |
8İzleyin | CVE-2005-3088İstismar yok | fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which fetchmail · fetchmail · CWE-200 | Düşük2,1 | — | %0,5 | 27 Eki 2005 |
8İzleyin | CVE-2001-1378İstismar yok | fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.fetchmail · fetchmail · CWE-59 | Düşük2,1 | — | %0,3 | 6 Eyl 2001 |
- CVE-2001-100942Planlayın
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory a
KritikCVSS 10,0Kavram kanıtıEPSS %7fetchmail · fetchmail31 Ağu 2001
- CVE-2001-010141Planlayın
Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.
KritikCVSS 10,0İstismar yokEPSS %2fetchmail · fetchmail12 Şub 2001
- CVE-2001-081932İzleyin
A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email head
YüksekCVSS 7,5İstismar yokEPSS %6fetchmail · fetchmail6 Ara 2001
- CVE-2006-586732İzleyin
fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances
YüksekCVSS 7,8İstismar yokEPSS %4fetchmail · fetchmail31 Ara 2006
- CVE-2006-597432İzleyin
fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial
YüksekCVSS 7,8İstismar yokEPSS %4fetchmail · fetchmail31 Ara 2006
- CVE-2005-434832İzleyin
fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (applica
YüksekCVSS 7,8İstismar yokEPSS %4fetchmail · fetchmail20 Ara 2005
- CVE-2002-136531İzleyin
Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local a
YüksekCVSS 7,5İstismar yokEPSS %5fetchmail · fetchmail23 Ara 2002
- CVE-2002-117431İzleyin
Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1
YüksekCVSS 7,5İstismar yokEPSS %5fetchmail · fetchmail11 Eki 2002
- CVE-2021-3638631İzleyin
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mai
YüksekCVSS 7,5İstismar yokEPSS %3fetchmail · fetchmail30 Tem 2021
- CVE-2010-056228İzleyin
The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, a
OrtaCVSS 6,8İstismar yokEPSS %2fetchmail · fetchmail8 Şub 2010
- CVE-2009-266625İzleyin
socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an
OrtaCVSS 6,4İstismar yokEPSS %2fetchmail · fetchmail7 Ağu 2009
- CVE-2012-348224İzleyin
Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (c
OrtaCVSS 5,8İstismar yokEPSS %2fetchmail · fetchmail21 Ara 2012
- CVE-2021-3927223İzleyin
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUT
OrtaCVSS 5,9İstismar yokEPSS %1fetchmail · fetchmail30 Ağu 2021
- CVE-2005-233522İzleyin
Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute
OrtaCVSS 5,0İstismar yokEPSS %6fetchmail · fetchmail27 Tem 2005
- CVE-2006-032121İzleyin
fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages tha
OrtaCVSS 5,0İstismar yokEPSS %4fetchmail · fetchmail23 Oca 2006
- CVE-2011-194721İzleyin
fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote s
OrtaCVSS 5,0İstismar yokEPSS %3fetchmail · fetchmail2 Haz 2011
- CVE-2003-079221İzleyin
Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (cr
OrtaCVSS 5,0İstismar yokEPSS %2fetchmail · fetchmail17 Kas 2003
- CVE-2002-117521İzleyin
The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a mal
OrtaCVSS 5,0İstismar yokEPSS %2fetchmail · fetchmail11 Eki 2002
- CVE-2007-456521İzleyin
sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) by
OrtaCVSS 5,0İstismar yokEPSS %2fetchmail · fetchmail27 Ağu 2007
- CVE-2002-014620İzleyin
fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to
OrtaCVSS 5,0İstismar yokEPSS %1fetchmail · fetchmail25 Haz 2002
- CVE-2008-271118İzleyin
fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persi
OrtaCVSS 4,3İstismar yokEPSS %3fetchmail · fetchmail16 Haz 2008
- CVE-2010-116718İzleyin
fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which a
OrtaCVSS 4,3İstismar yokEPSS %2fetchmail · fetchmail7 May 2010
- CVE-2005-30888İzleyin
fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which
DüşükCVSS 2,1İstismar yokEPSS %0fetchmail · fetchmail27 Eki 2005
- CVE-2001-13788İzleyin
fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.
DüşükCVSS 2,1İstismar yokEPSS %0fetchmail · fetchmail6 Eyl 2001