CVE Tools

Neomutt

15 CVEs tracked since 2018. Since Jul 2018, none of them reached CISA KEV.

Neomutt CVEs per month

Jul 2018 to Jul 2018. Point at a month, or focus the strip and use the arrow keys.
Neomutt CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-07150

Products

The products that kept showing up in Neomutt's monthly top three, with their CVEs summed over those months.

  1. Neomutt151 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Neomutt.

  1. CVE-2024-49395Mutt: neomutt: bcc email header field is indirectly leaked by cryptographic info block5.3
  2. CVE-2024-49394Mutt: neomutt: in-reply-to email header field it not protected by cryptograpic signing5.3
  3. CVE-2024-49393Mutt: neomutt: to and cc email header fields are not protected by cryptographic signing6.5
  4. CVE-2021-32055Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ...9.1
  5. CVE-2020-28896Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and...5.3
  6. CVE-2020-14954Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g...5.9
  7. CVE-2018-14353An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.9.8
  8. CVE-2018-14360An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.9.8
  9. CVE-2018-14359An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.9.8
  10. CVE-2018-14349An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.9.8
  11. CVE-2018-14361An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.9.8
  12. CVE-2018-14356An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.9.8
  13. CVE-2018-14354An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command ...9.8
  14. CVE-2018-14351An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.9.8
  15. CVE-2018-14350An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long INTERNALDATE field.9.8

The record

Peak rank
#36 in Jul 2018
Busiest month shown
Jul 2018, 15 CVEs
Months with a KEV entry
0 since Jul 2018
Monthly snapshots
1 since 2018
Neomutt's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store