Fetchmail is a widely used open-source mail retrieval and forwarding utility that sits in the email ingestion path of many mail servers and personal systems, providing a narrow but deeply embedded product scope. The recurring vulnerability profile centers on the fetchmail daemon itself and clusters around input-validation deficiencies, memory-boundary violations, and sensitive-information handling practices, reflecting the parsing complexity inherent to email protocol implementation. Defenders should treat fetchmail advisories as requiring prompt attention given the utility's role in direct credential handling and mailbox access, even where individual disclosures may not achieve critical severity; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fetchmail over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-1009HIGH Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negati | Aug 31, 2001 | 10.0 | 37 | NO | YES |
CVE-2002-1174HIGH Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly pro | Oct 11, 2002 | 7.5 | 26 | NO | NO |
CVE-2001-0101HIGH Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command. | Feb 12, 2001 | 10.0 | 26 | NO | NO |
CVE-2021-36386HIGH report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service o | Jul 30, 2021 | 7.5 | 25 | NO | NO |
CVE-2005-4348HIGH fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application crash) by sending messages without | Dec 21, 2005 | 7.8 | 24 | NO | NO |
CVE-2010-0562MEDIUM The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial | Feb 8, 2010 | 6.8 | 23 | NO | NO |
CVE-2021-39272MEDIUM Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH. | Aug 30, 2021 | 5.9 | 22 | NO | NO |
CVE-2011-1947MEDIUM fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (app | Jun 2, 2011 | 5.0 | 21 | NO | NO |
CVE-2009-2666MEDIUM socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in- | Aug 7, 2009 | 6.4 | 21 | NO | NO |
CVE-2006-5867HIGH fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to | Dec 31, 2006 | 7.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fetchmail.
Media articles that mention a CVE ID that affects a product developed by Fetchmail — matched by CVE ID, not by vendor name.