<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:29:28.819097+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:1964</id>
    <title>ALSA-2022:1964 — Moderate: fetchmail security update</title>
    <updated>2026-10-03T18:29:28.834660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: fetchmail</p>
<p>Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so the user can read it through their favorite mail client.</p>
<p>Security Fix(es):</p>
<p>* fetchmail: DoS or information disclosure when logging long messages (CVE-2021-36386)</p>
<p>* fetchmail: STARTTLS session encryption bypassing (CVE-2021-39272)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:1964"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-qk25555</id>
    <title>CLEANSTART-2024-QK25555 — Fetchmail before 6</title>
    <updated>2026-10-03T18:29:28.834726+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: fetchmail</p>
<p>Security vulnerability affects the fetchmail package. Fetchmail before 6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-qk25555"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-30558</id>
    <title>EUVD-2026-30558</title>
    <updated>2026-10-03T18:29:28.834748+00:00</updated>
    <content>EUVD-2026-30558</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-30558"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-39272</id>
    <title>fkie_cve-2021-39272</title>
    <updated>2026-10-03T18:29:28.834761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-39272"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x8j8-pwr7-frjw</id>
    <title>GHSA-x8j8-pwr7-frjw</title>
    <updated>2026-10-03T18:29:28.834781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x8j8-pwr7-frjw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-39272</id>
    <title>gsd-2021-39272</title>
    <updated>2026-10-03T18:29:28.834794+00:00</updated>
    <content>gsd-2021-39272</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-39272"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-39272</id>
    <title>msrc_CVE-2021-39272 — Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances such as a certain situation…</title>
    <updated>2026-10-03T18:29:28.834805+00:00</updated>
    <content>msrc_CVE-2021-39272</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-39272"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1360</id>
    <title>OESA-2021-1360 — fetchmail security update</title>
    <updated>2026-10-03T18:29:28.834821+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: fetchmail, openEuler:20.03-LTS-SP2: fetchmail</p>
<p>Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections.

Security Fix(es):

Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.(CVE-2021-39272)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1360"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1416-1</id>
    <title>openSUSE-SU-2021:1416-1 — Security update for fetchmail</title>
    <updated>2026-10-03T18:29:28.834844+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for fetchmail</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:1416-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:3492-1</id>
    <title>SUSE-SU-2021:3492-1 — Security update for fetchmail</title>
    <updated>2026-10-03T18:29:28.834858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for fetchmail</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:3492-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-39272</id>
    <title>UBUNTU-CVE-2021-39272</title>
    <updated>2026-10-03T18:29:28.834871+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: fetchmail, Ubuntu:18.04:LTS: fetchmail, Ubuntu:20.04:LTS: fetchmail</p>
<p>Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-39272"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</id>
    <title>WID-SEC-W-2022-0302 — Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administrator…</title>
    <updated>2026-10-03T18:29:28.834889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302"/>
  </entry>
</feed>
