Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mutt

First CVE: Jul 28, 1998Active for: 28 yearsTotal CVEs: 52
38.3
VTI Score
Medium

Mutt is a text-based email client widely deployed across Unix and Linux systems, representing a focused but persistently maintained product serving technical and security-conscious users. Its vulnerability profile skews strongly toward critical-severity outcomes, concentrated in a narrow product line but reflecting the memory-safety challenges inherent to a C-based mail parser handling untrusted message content. The recurring weakness classes—improper input validation, buffer overflows, out-of-bounds writes, and memory-bounds violations—are characteristic of the parsing demands placed on email processing code and have recurred across the vendor's release history. Defenders should apply Mutt updates promptly despite the vendor's niche position, as the product's presence in security operations centers and administratively sensitive systems elevates the impact of parser-level flaws. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
52
Total CVEs
More Total CVEs than 98% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mutt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 28, 1998
27 years ago
Most Recent CVE
May 4, 2026
81 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (52 CVEs).

52 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-14359CRITICAL
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
Jul 17, 20189.831NONO
CVE-2018-14356CRITICAL
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
Jul 17, 20189.831NONO
CVE-2018-14354CRITICAL
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the m
Jul 17, 20189.831NONO
CVE-2018-14350CRITICAL
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long INTERNALDATE field.
Jul 17, 20189.831NONO
CVE-2018-14362CRITICAL
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demo
Jul 17, 20189.830NONO
CVE-2018-14358CRITICAL
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field.
Jul 17, 20189.830NONO
CVE-2018-14357CRITICAL
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the m
Jul 17, 20189.830NONO
CVE-2018-14353CRITICAL
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.
Jul 17, 20189.830NONO
CVE-2018-14351CRITICAL
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.
Jul 17, 20189.830NONO
CVE-2018-14349CRITICAL
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.
Jul 17, 20189.830NONO
View all 52 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products52 CVEs
17%
40%
19%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (3.8%)
Network29 (55.8%)
Unknown21 (40.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (38.5%)
High11 (21.2%)
Unknown21 (40.4%)
User Interaction
None26 (50.0%)
Unknown21 (40.4%)
Required5 (9.6%)
Privileges Required
Low2 (3.8%)
High0 (0.0%)
None29 (55.8%)
Unknown21 (40.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (52 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.9% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mutt.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mutt — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mutt's Products

View all 4 CNAs →

Top CWEs