Known Vulnerabilities for products from Getmail

Listed below are 5 of the newest known vulnerabilities associated with the vendor "Getmail".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2014-7275 The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which a... 5.8 - MEDIUM 2014-10-08 2014-12-22
CVE-2014-7274 The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the subj... 5.8 - MEDIUM 2014-10-08 2014-12-22
CVE-2014-7273 The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which a... 6.8 - MEDIUM 2014-10-08 2014-12-19
CVE-2004-0881 getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary d... 2.1 - LOW 2005-01-27 2017-07-11
CVE-2004-0880 getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox f... 1.2 - LOW 2005-01-27 2017-07-11