Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-61085
HistoryAug 03, 2021 - 12:00 a.m.

Claws Mail Input Validation Error Vulnerability

2021-08-0300:00:00
China National Vulnerability Database
www.cnvd.org.cn
4

0.001 Low

EPSS

Percentile

43.5%

Claws Mail is an open source email client and news aggregator written in the GTK language. claws mail suffers from an injection vulnerability that stems from the textview_uri_security_check function in textview.c in Claws Mail prior to version 3.18.0, and from the 3.7.0 Sylpheed before version 3.7.0, which does not perform sufficient checks on links before accepting a click. No detailed vulnerability details are currently available.

CPENameOperatorVersion
claws mail claws-maillt3.18.0

0.001 Low

EPSS

Percentile

43.5%