Vulnerabilities > Fetchmail > Fetchmail > 5.9.11

DATE CVE VULNERABILITY TITLE RISK
2003-11-17 CVE-2003-0792 Resource Management Errors vulnerability in Fetchmail
Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.
network
low complexity
fetchmail CWE-399
5.0
2002-12-23 CVE-2002-1365 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Fetchmail
Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header with a large number of local addresses.
network
low complexity
fetchmail CWE-119
7.5
2002-10-11 CVE-2002-1175 Improper Input Validation vulnerability in Fetchmail
The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to read data beyond the expected boundary.
network
low complexity
fetchmail CWE-20
5.0
2002-10-11 CVE-2002-1174 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Fetchmail
Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (2) via long Received: headers, which are not properly parsed by the parse_received function.
network
low complexity
fetchmail CWE-119
7.5