Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fetchmail

First CVE: Feb 12, 2001Active for: 25 yearsTotal CVEs: 25
35.4
VTI Score
Medium

Fetchmail is a widely used open-source mail retrieval and forwarding utility that sits in the email ingestion path of many mail servers and personal systems, providing a narrow but deeply embedded product scope. The recurring vulnerability profile centers on the fetchmail daemon itself and clusters around input-validation deficiencies, memory-boundary violations, and sensitive-information handling practices, reflecting the parsing complexity inherent to email protocol implementation. Defenders should treat fetchmail advisories as requiring prompt attention given the utility's role in direct credential handling and mailbox access, even where individual disclosures may not achieve critical severity; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fetchmail over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2001
25 years ago
Most Recent CVE
Oct 4, 2025
293 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2001-1009HIGH
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negati
Aug 31, 200110.037NOYES
CVE-2002-1174HIGH
Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly pro
Oct 11, 20027.526NONO
CVE-2001-0101HIGH
Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.
Feb 12, 200110.026NONO
CVE-2021-36386HIGH
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service o
Jul 30, 20217.525NONO
CVE-2005-4348HIGH
fetchmail before 6.3.1 and before 6.2.5.5, when configured for multidrop mode, allows remote attackers to cause a denial of service (application crash) by sending messages without
Dec 21, 20057.824NONO
CVE-2010-0562MEDIUM
The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial
Feb 8, 20106.823NONO
CVE-2021-39272MEDIUM
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
Aug 30, 20215.922NONO
CVE-2011-1947MEDIUM
fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (app
Jun 2, 20115.021NONO
CVE-2009-2666MEDIUM
socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-
Aug 7, 20096.421NONO
CVE-2006-5867HIGH
fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to
Dec 31, 20067.821NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
56%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (12.0%)
Unknown22 (88.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.0%)
High2 (8.0%)
Unknown22 (88.0%)
User Interaction
None3 (12.0%)
Unknown22 (88.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (12.0%)
Unknown22 (88.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fetchmail.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fetchmail — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fetchmail's Products

View all 2 CNAs →

Top CWEs