Getmail is a mail-retrieval utility with a narrow but resilient footprint in mail-server and automation deployments, where it retrieves and processes messages from remote accounts. Its limited disclosure history reflects a focused scope; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getmail over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-7273MEDIUM The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof IMAP servers | Oct 8, 2014 | 6.8 | 18 | NO | NO |
CVE-2014-7275MEDIUM The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof POP3 servers | Oct 8, 2014 | 5.8 | 16 | NO | NO |
CVE-2014-7274MEDIUM The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, | Oct 8, 2014 | 5.8 | 16 | NO | NO |
getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in th | Jan 27, 2005 | 2.1 | 14 | NO | NO |
getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file. | Jan 27, 2005 | 1.2 | 13 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getmail.
Media articles that mention a CVE ID that affects a product developed by Getmail — matched by CVE ID, not by vendor name.