Vulnerabilities
Vulnerable Software
Mutt:  >> Mutt  >> 1.5.20  Security Vulnerabilities
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
CVSS Score
9.8
EPSS Score
0.054
Published
2018-07-17
Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
CVSS Score
5.0
EPSS Score
0.014
Published
2014-03-14
Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.
CVSS Score
5.8
EPSS Score
0.006
Published
2011-03-16
mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVSS Score
6.8
EPSS Score
0.004
Published
2009-10-23


Contact Us

Shodan ® - All rights reserved