Marlam maintains a narrow set of mail-handling utilities, including the POP3 client mpop and SMTP submission tool msmtp, that serve focused roles in email infrastructure and scripting environments. The observed vulnerability profile centers on improper certificate validation, a weakness class that reflects the TLS-integration demands of these mail-protocol tools. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Marlam over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-8337MEDIUM In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. | Feb 13, 2019 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Marlam.
Media articles that mention a CVE ID that affects a product developed by Marlam — matched by CVE ID, not by vendor name.