📦

mutt

Vendor: mutt

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 11 Remote Access
Total CVEs 53 Total Indexed
Avg. EPSS 1.75% Exploit Prob.
Latest CVE CVE-2024-49395 Nov 12

Security Vulnerability Index

Page 5 / 6
7.5 CVSS

Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.

EPSS: 0.93%
7.5 CVSS

Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.

EPSS: 2.18%
7.5 CVSS

Vulnerability in RFC822 address parser in mutt before 1.2.5.1 and mutt 1.3.x before 1.3.25 allows remote attackers to execute arbitrary commands via an improperly terminated comment or phrase in the address list.

EPSS: 2.59%
7.5 CVSS

Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.

EPSS: 1.01%