getmail CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

getmail vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to getmail, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2014-7275 The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof POP3 servers and obtain sensitive information via a crafted certificate. [email protected] 5.8 0.18% 2014-10-08 2026-05-06
CVE-2014-7274 The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate from a recognized Certification Authority. [email protected] 5.8 0.18% 2014-10-08 2026-05-06
CVE-2014-7273 The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate. [email protected] 6.8 0.21% 2014-10-08 2026-05-06
CVE-2004-0881 getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir. [email protected] 2.1 0.07% 2005-01-27 2026-04-16
CVE-2004-0880 getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file. [email protected] 1.2 0.08% 2005-01-27 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence