Vulnerabilities > Claws Mail
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-07-30 | CVE-2021-37746 | Open Redirect vulnerability in multiple products textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click. | 6.1 |
2020-07-28 | CVE-2020-16094 | Uncontrolled Recursion vulnerability in multiple products In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree. | 7.5 |
2020-07-23 | CVE-2020-15917 | common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled. | 9.8 |
2019-11-25 | CVE-2012-5527 | Insufficiently Protected Credentials vulnerability in Claws-Mail Vcalendar Claws Mail vCalendar plugin: credentials exposed on interface | 5.5 |
2019-04-07 | CVE-2019-10735 | Cleartext Transmission of Sensitive Information vulnerability in Claws-Mail Mail 3.14.1 In Claws Mail 3.14.1, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. | 4.3 |
2016-04-11 | CVE-2015-8708 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Claws-Mail 3.13.1 Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. | 7.3 |
2016-04-11 | CVE-2015-8614 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. | 7.3 |