Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fetchmail MEDIUM 5.8
CVE-2012-3482

Fetchmail 5.0.8 through 6.3.21, when using NTLM authentication in debug mode, allows remote NTLM servers to (1) cause a denial of service (crash and …

Patch available
Fix from $1,600 2012-12-21
Fetchmail MEDIUM 5.0
CVE-2011-1947

fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to…

Mitigation only
Fix from $1,600 2011-06-02
Fetchmail MEDIUM 6.8
CVE-2010-0562

The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows rem…

Mitigation only
Fix from $1,600 2010-02-08
Fetchmail MEDIUM 6.4
CVE-2009-2666

socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 ce…

Fix: after 6.3.10
Fix from $1,600 2009-08-07
Fetchmail MEDIUM 5.0
CVE-2007-4565

sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) by refusing…

Fix: after 6.3.9
Fix from $1,600 2007-08-28
Fetchmail HIGH 7.8
CVE-2006-5867

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, wh…

Fix: after 6.3.6
Fix from $1,950 2006-12-31
Fetchmail HIGH 7.8
CVE-2006-5974

fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial of servic…

Patch available
Fix from $1,950 2006-12-31
Fetchmail MEDIUM 5.0
CVE-2006-0321

fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a…

Patch available
Fix from $1,600 2006-01-24
Fetchmail HIGH 7.8
CVE-2005-4348

fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application cras…

Fix: 6.2.5.5 / 6.3.1+
Fix from $1,950 2005-12-21
Fetchmail MEDIUM 5.0
CVE-2005-2335EPSS 6%

Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary…

Fix: after 6.2.5.1
Fix from $1,600 2005-07-27
Fetchmail MEDIUM 5.0
CVE-2003-0792

Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via …

Fix: after 6.2.4
Fix from $1,600 2003-11-17
Fetchmail HIGH 7.5
CVE-2002-1365

Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses,…

Fix: after 6.1.3
Fix from $1,950 2002-12-23
Fetchmail HIGH 7.5
CVE-2002-1174

Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long he…

Fix: after 6.0.0
Fix from $1,950 2002-10-11
Fetchmail MEDIUM 5.0
CVE-2002-1175

The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DN…

Fix: after 6.0.0
Fix from $1,600 2002-10-11
Fetchmail MEDIUM 5.0
CVE-2002-0146

fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to overwrite…

Fix: after 5.9.8
Fix from $1,600 2002-06-25
Fetchmail HIGH 7.5
CVE-2001-0819EPSS 6%

A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email header.

Fix: after 5.8.5
Fix from $1,950 2001-12-06
Fetchmail HIGH 10.0
CVE-2001-1009EPSS 7%

Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possib…

Fix: after 5.8.14
Fix from $1,950 2001-08-31
Fetchmail HIGH 10.0
CVE-2001-0101

Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.

Fix: after 5.5.0
Fix from $1,950 2001-02-12