CRITICAL9.8CVE-2020-15917common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled. from 0, < 3.17.6-1
HIGH7.5CVE-2020-16094In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recurs… from 0, < 3.17.7-1
HIGH7.3CVE-2015-8708Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified im… from 0, < 3.13.1-1.1
HIGH7.3claws-mail - security update
from 0, < 3.8.1-2+deb7u1
HIGH7.3claws-mail - security update
from 0, < 3.13.1-1
HIGH7.3claws-mail - security update
from 0, < 3.7.6-4+squeeze2
MEDIUM6.1textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks bef…
from 0
MEDIUM4.3In Claws Mail 3.14.1, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart ema…
from 0
—plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it e…
from 0, < 3.10.1-1
—Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Stream Reader allows remote attackers to cause a denial of servi…
from 0, < 3.11.1-2
—The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of service (NULL pointer d…
from 0, < 3.8.1-2
—sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[US…
from 0, < 3.1.0-2
—icedove - several vulnerabilities
from 0, < 2.9.1-1