📦

balsa

Vendor: stuart_parmenter

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 2 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 0.76% Exploit Prob.
Latest CVE CVE-2020-16118 Jul 29

Security Vulnerability Index

Page 1 / 1
7.5 CVSS

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c.

EPSS: 0.62%
6.5 CVSS

In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.

EPSS: 0.46%
6.8 CVSS

Stack-based buffer overflow in the ir_fetch_seq function in balsa before 2.3.20 might allow remote IMAP servers to execute arbitrary code via a long response to a FETCH command.

EPSS: 0.99%
7.5 CVSS

The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large mailbox size values that cause either integer signedness errors or integer overflow errors.

EPSS: 0.89%
5.0 CVSS

The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.

EPSS: 0.84%