Vulnerabilities > Mutt > Mutt > 1.5.17

DATE CVE VULNERABILITY TITLE RISK
2018-07-17 CVE-2018-14349 Improper Input Validation vulnerability in multiple products
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
network
low complexity
debian mutt neomutt canonical CWE-20
7.5
2014-03-14 CVE-2014-0467 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.
network
low complexity
mutt opensuse CWE-119
5.0
2009-10-23 CVE-2009-3766 Cryptographic Issues vulnerability in Mutt 1.5.16/1.5.17/1.5.18
mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
network
mutt openssl CWE-310
6.8