The Libetpan Project maintains a mail-client library that, despite limited scope as a single focused component, sits within email applications and messaging systems where parsing untrusted protocol data is inherent to its function. Its observed vulnerability signal centers on NULL-pointer dereference and injection-class weakness issues that arise from parsing email structures and protocol elements, reflecting the complexity of handling diverse and malformed mail formats. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libetpan Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8825HIGH A null dereference vulnerability has been found in the MIME handling component of LibEtPan before 1.8, as used in MailCore and MailCore 2. A crash can occur in low-level/imf/mailim | May 8, 2017 | 7.5 | 26 | NO | NO |
CVE-2020-15953HIGH LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" | Jul 27, 2020 | 7.4 | 25 | NO | NO |
CVE-2022-4121MEDIUM In libetpan a null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c was found that could lead to a remote denial of service or other pote | Jan 17, 2023 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libetpan Project.
Media articles that mention a CVE ID that affects a product developed by Libetpan Project — matched by CVE ID, not by vendor name.