Search Results
There are 9 CVE entries that match your search.
| Name |
Description |
| CVE-2017-17517 |
libsylph/utils.c in Sylpheed through 3.6 does not validate strings
before launching the program specified by the BROWSER environment
variable, which might allow remote attackers to conduct
argument-injection attacks via a crafted URL.
|
| CVE-2007-2958 |
Format string vulnerability in the inc_put_error function in src/inc.c
in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0,
allows remote POP3 servers to execute arbitrary code via format string
specifiers in crafted replies.
|
| CVE-2007-1267 |
Sylpheed 2.2.7 and earlier does not properly use the --status-fd
argument when invoking GnuPG, which prevents Sylpheed from visually
distinguishing between signed and unsigned portions of OpenPGP
messages with multiple components, which allows remote attackers to
forge the contents of a message without detection.
|
| CVE-2006-2920 |
Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote
attackers to bypass the URI check functionality and makes it easier to
conduct phishing attacks via a URI that begins with a space character.
|
| CVE-2005-3354 |
Stack-based buffer overflow in the ldif_get_line function in ldif.c of
Sylpheed before 2.1.6 allows user-assisted attackers to execute
arbitrary code by having local users import LDIF files with long
lines.
|
| CVE-2005-0926 |
Buffer overflow in Sylpheed before 1.0.4 allows remote attackers to
cause a denial of service (crash) and possibly execute arbitrary code
via attachments with MIME-encoded file names.
|
| CVE-2005-0667 |
Buffer overflow in Sylpheed before 1.0.3 and other versions before
1.9.5 allows remote attackers to execute arbitrary code via an e-mail
message with certain headers containing non-ASCII characters that are
not properly handled when the user replies to the message.
|
| CVE-2003-0852 |
Format string vulnerability in send_message.c for Sylpheed-claws 0.9.4
through 0.9.6 allows remote SMTP servers to cause a denial of service
(crash) in sylpheed via format strings in an error message.
|
| CVE-2003-0300 |
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP
servers to cause a denial of service (crash) via certain large literal
size values that cause either integer signedness errors or integer
overflow errors.
|