<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:47:30.342138+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:1964</id>
    <title>ALSA-2022:1964 — Moderate: fetchmail security update</title>
    <updated>2026-10-03T20:47:31.240201+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: fetchmail</p>
<p>Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so the user can read it through their favorite mail client.</p>
<p>Security Fix(es):</p>
<p>* fetchmail: DoS or information disclosure when logging long messages (CVE-2021-36386)</p>
<p>* fetchmail: STARTTLS session encryption bypassing (CVE-2021-39272)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:1964"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03928</id>
    <title>bdu:2021-03928</title>
    <updated>2026-10-03T20:47:31.240348+00:00</updated>
    <content>bdu:2021-03928</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-yi47904</id>
    <title>CLEANSTART-2024-YI47904 — report_vbuild in report</title>
    <updated>2026-10-03T20:47:31.240386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: fetchmail</p>
<p>Security vulnerability affects the fetchmail package. report_vbuild in report.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-yi47904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-29372</id>
    <title>EUVD-2026-29372</title>
    <updated>2026-10-03T20:47:31.240432+00:00</updated>
    <content>EUVD-2026-29372</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-29372"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-36386</id>
    <title>fkie_cve-2021-36386</title>
    <updated>2026-10-03T20:47:31.240458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-36386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rr6c-95pp-cpgf</id>
    <title>GHSA-rr6c-95pp-cpgf</title>
    <updated>2026-10-03T20:47:31.240494+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rr6c-95pp-cpgf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-36386</id>
    <title>gsd-2021-36386</title>
    <updated>2026-10-03T20:47:31.240520+00:00</updated>
    <content>gsd-2021-36386</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-36386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-36386</id>
    <title>msrc_CVE-2021-36386 — report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument w…</title>
    <updated>2026-10-03T20:47:31.240537+00:00</updated>
    <content>msrc_CVE-2021-36386</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-36386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1314</id>
    <title>OESA-2021-1314 — fetchmail security update</title>
    <updated>2026-10-03T20:47:31.240565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: fetchmail, openEuler:20.03-LTS-SP2: fetchmail</p>
<p>Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections.

Security Fix(es):

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.(CVE-2021-36386)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1183-1</id>
    <title>openSUSE-SU-2021:1183-1 — Security update for fetchmail</title>
    <updated>2026-10-03T20:47:31.240604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for fetchmail</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:1183-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:2771-1</id>
    <title>SUSE-SU-2021:2771-1 — Security update for fetchmail</title>
    <updated>2026-10-03T20:47:31.240641+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for fetchmail</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:2771-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-36386</id>
    <title>UBUNTU-CVE-2021-36386</title>
    <updated>2026-10-03T20:47:31.240698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: fetchmail, Ubuntu:18.04:LTS: fetchmail, Ubuntu:20.04:LTS: fetchmail</p>
<p>report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-36386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1525</id>
    <title>WID-SEC-W-2022-1525 — fetchmail: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T20:47:31.240758+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in fetchmail ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1525"/>
  </entry>
</feed>
