Fetchmail suffers from a denial of service vulnerability in the STARTTLS protocol phases. Versions 5.9.9 up to and including 6.3.19 are affected.
1489e4cc4ce52c41a58894cd8f7579dfc567612fec359ebe3eb13209676c068f
Fetchmail versions 4.6.3 through 6.3.16 suffer from a denial of service vulnerability in debug mode.
c8acef1aeacf591fd77b9ec4a3ca6e3b6bcb8df278661e852d11d431d6c64b01
Fetchmail versions 6.3.10 and below suffer from an improper SSL certificate subject verification vulnerability.
ce7096d8ac83ac8f9f069b1910a6aa91898577d3165d040410eeb7f62efaf3fc
Fetchmail version 1.02 suffers from a password disclosure vulnerability where the configuration file stores the password in clear text prior to setting the proper permissions.
cb466b5def2824910541b860561776367b2d03a1c01eaedb55b9fe90779e4adb
Leafnode versions 1.9.48 to 1.11.1 suffer from a denial of service vulnerability.
30b6c7c1e8d7eeb30cd82999c84bd5e80690a1a2b8ceede25323b0633cea4b3d
Fetchmail version 1.02 suffers from a remote code injection vulnerability.
fc3f1ce80d30fc5169baa1476c5710f9cd636aec98c35ccdc729e1c419f34d2c
Some dynamically linked binary builds of the CVSup package contain untrusted paths in the ELF RPATH fields of the executables which may allow for local privilege escalation.
b8782bca72a905590f6df6d37502a533b73ad0fe9fb35cea32cce7475f90ab88
fetchnews, the NNTP client from leafnode, suffers from a possible denial of service vulnerability that can be triggered via malformatted Usenet news articles. Affected version: 1.01.
7942d464cd35c3cc8520ff12dc5a2bdaa10ee01de0f4d9457c7d2142218dcc81
SuSE 8.1's "gfxmenu" which is configured into GRUB by default on many machines allows the user to pass in additional kernel boot parameters without entering the password, allowing users who can locally reboot the machine to easily spawn a root shell.
8835b98c7e6cc1122e66d91619047a0fcc3b5ad373a989202c6f9b7dbbe592f8