Search CVE reports


Toggle filters

11 – 16 of 16 results


CVE-2017-17843

High priority

Some fixes available 3 of 4

An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a...

1 affected package

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
enigmail
Show less packages

CVE-2017-17688

Medium priority
Ignored

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that...

1 affected package

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
enigmail Not affected
Show less packages

CVE-2014-5369

Low priority

Some fixes available 3 of 4

Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.

1 affected package

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
enigmail
Show less packages

CVE-2007-1264

Medium priority
Ignored

Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing between signed and unsigned portions of OpenPGP messages with...

1 affected package

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
enigmail
Show less packages

CVE-2006-5877

Medium priority
Fixed

The enigmail extension before 0.94.2 does not properly handle large, encrypted file e-mail attachments, which allows remote attackers to cause a denial of service (crash), as demonstrated with Mozilla Thunderbird.

1 affected package

enigmail

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
enigmail
Show less packages

CVE-2005-3256

Medium priority
Fixed

The key selection dialogue in Enigmail before 0.92.1 can incorrectly select a key with a user ID that does not have additional information, which allows parties with that key to decrypt the message.

2 affected packages

enigmail, enigmail-mailnews

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
enigmail
enigmail-mailnews
Show less packages