RSS   Vulnerabilities for 'Claws-mail'   RSS

2020-07-28
 
CVE-2020-16094

CWE-674
 

 
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.

 
2020-07-23
 
CVE-2020-15917

NVD-CWE-noinfo
 

 
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.

 
2016-04-11
 
CVE-2015-8708

 

 
Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8614.

 
 
CVE-2015-8614

CWE-119
 

 
Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.

 
2014-10-15
 
CVE-2014-2576

CWE-310
 

 
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

 
2012-10-22
 
CVE-2012-4507

 

 
The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted email.

 

 >>> Vendor: Claws-mail 3 Products
MAIL
Claws-mail
Vcalendar


Copyright 2024, cxsecurity.com

 

Back to Top