Vulnerabilities > Claws Mail

DATE CVE VULNERABILITY TITLE RISK
2021-07-30 CVE-2021-37746 Open Redirect vulnerability in multiple products
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
6.1
2020-07-28 CVE-2020-16094 Uncontrolled Recursion vulnerability in multiple products
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
network
low complexity
claws-mail fedoraproject CWE-674
7.5
2020-07-23 CVE-2020-15917 common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
network
low complexity
claws-mail fedoraproject opensuse
critical
9.8
2019-11-25 CVE-2012-5527 Insufficiently Protected Credentials vulnerability in Claws-Mail Vcalendar
Claws Mail vCalendar plugin: credentials exposed on interface
local
low complexity
claws-mail CWE-522
5.5
2019-04-07 CVE-2019-10735 Cleartext Transmission of Sensitive Information vulnerability in Claws-Mail Mail 3.14.1
In Claws Mail 3.14.1, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email.
network
low complexity
claws-mail CWE-319
4.3
2016-04-11 CVE-2015-8708 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Claws-Mail 3.13.1
Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.
network
low complexity
claws-mail CWE-119
7.3
2016-04-11 CVE-2015-8614 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.
network
low complexity
claws-mail opensuse CWE-119
7.3