-Infinity
0

Vendor Risk Score

See how mutt compares to other vendors in security performance

View Risk Score →

Mutt MuttNull Pointer Dereference

Risk 14
Severity
2.5
First published (updated )

Mutt Muttmutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.

Risk 20
Severity
3.7
First published (updated )

Mutt MuttIn mutt before 2.3.2, the imap_auth_gss security level is mishandled.

Risk 20
Severity
3.7
First published (updated )

Mutt Muttmutt before 2.3.2 does not check for '\0' in url_pct_decode.

Risk 20
Severity
3.7
First published (updated )

Mutt Muttmutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.

Risk 20
Severity
3.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mutt Muttmutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

Risk 20
Severity
3.7
First published (updated )

oss-secFwd: mutt 2.3.2 leased

redhat Enterprise LinuxMutt: neomutt: bcc email header field is indirectly leaked by cryptographic info block

Risk 19
Severity
5.3
EPSS
0.03%
First published (updated )

Mutt MuttIn mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc …

Risk 5
Severity
1
First published (updated )

redhat Enterprise LinuxMutt: neomutt: in-reply-to email header field it not protected by cryptograpic signing

Risk 19
Severity
5.3
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mutt MuttIn mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing whi…

Risk 5
Severity
1
First published (updated )

redhat Enterprise LinuxMutt: neomutt: to and cc email header fields are not protected by cryptographic signing

Risk 41
Severity
7.4
EPSS
0.02%
First published (updated )

neomutt neomuttIn neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which al…

Risk 19
Severity
4
First published (updated )

mutt 2.2.12 security update

mutt 2.2.12 security update

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ubuntu/muttUndefined Behavior for Input to API in Mutt

Risk 39
Severity
6.5
First published (updated )

ubuntu/muttUndefined Behavior for Input to API in Mutt

Risk 35
Severity
5.7
First published (updated )

Mutt MuttBuffer Overflow

Risk 27
Severity
5.3
First published (updated )

Mutt MuttLast updated 16 January 2025

Risk 66
Severity
9.1
First published (updated )

debian/muttrfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavail…

Risk 37
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mutt MuttLast updated 16 January 2025

Risk 31
Severity
5.3
First published (updated )

Canonical Ubuntu LinuxLast updated 25 August 2025

Risk 37
Severity
5.9
First published (updated )

Canonical Ubuntu LinuxLast updated 25 August 2025

Risk 37
Severity
5.8
First published (updated )

Canonical Ubuntu LinuxLast updated 25 August 2025

Risk 37
Severity
5.9
First published (updated )

Debian Debian LinuxMutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests …

Risk 32
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mutt MuttMutt vulnerabilities

Risk 23
First published (updated )
Advisory
USN-3719-1

Mutt MuttMutt vulnerabilities

Risk 23
First published (updated )
Advisory
USN-3719-2

Canonical Ubuntu LinuxBuffer Overflow

Risk 88
Severity
9.8
First published (updated )

Canonical Ubuntu LinuxBuffer Overflow

Risk 88
Severity
9.8
First published (updated )

redhat Enterprise Linux Server EusBuffer Overflow, Path Traversal

Risk 89
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203