JerikoOne

14 exploits Active since Jul 2018
CVE-2018-14349 WRITEUP CRITICAL WRITEUP
Mutt <1.10.1 - Info Disclosure
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.
CVSS 9.8
CVE-2018-14350 WRITEUP CRITICAL WRITEUP
Mutt <1.10.1 - Buffer Overflow
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long INTERNALDATE field.
CVSS 9.8
CVE-2018-14351 WRITEUP CRITICAL WRITEUP
Mutt <1.10.1 - Info Disclosure
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.
CVSS 9.8
CVE-2018-14352 WRITEUP CRITICAL WRITEUP
Mutt <1.10.1 - Buffer Overflow
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.
CVSS 9.8
CVE-2018-14353 WRITEUP CRITICAL WRITEUP
Mutt <1.10.1 - Info Disclosure
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.
CVSS 9.8
CVE-2018-14354 WRITEUP CRITICAL WRITEUP
Mutt <1.10.1 - Command Injection
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription.
CVSS 9.8
CVE-2018-14355 WRITEUP MEDIUM WRITEUP
Mutt <1.10.1 - Path Traversal
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.
CVSS 5.3
CVE-2018-14356 WRITEUP CRITICAL WRITEUP
Mutt <1.10.1 - Info Disclosure
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
CVSS 9.8
CVE-2018-14357 WRITEUP CRITICAL WRITEUP
Mutt <1.10.1 - Command Injection
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.
CVSS 9.8
CVE-2018-14358 WRITEUP CRITICAL WRITEUP
Mutt <1.10.1 - Buffer Overflow
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field.
CVSS 9.8
CVE-2018-14360 WRITEUP CRITICAL WRITEUP
NeoMutt <2018-07-16 - Buffer Overflow
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
CVSS 9.8
CVE-2018-14361 WRITEUP CRITICAL WRITEUP
NeoMutt <2018-07-16 - Memory Corruption
An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
CVSS 9.8
CVE-2018-14362 WRITEUP CRITICAL WRITEUP
Mutt <1.10.1 - Info Disclosure
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
CVSS 9.8
CVE-2018-14363 WRITEUP HIGH WRITEUP
NeoMutt <2018-07-16 - Path Traversal
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
CVSS 7.5