// For flags

CVE-2012-1103

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the message.

emacs/notmuch-mua.el en notmuch antes de v0.11.1, cuando se utiliza el interface Emacs, permite leer archivos de su elección a atacantes remotos con cierta ayuda de usuarios locales a través de etiquetas MML modificadas, que no están debidamente marcadas en una respuesta de correo electrónico podría ocasionar que cualquier tipo de fichero pudiera ser adjuntarse al mensaje.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-02-14 CVE Reserved
  • 2012-09-25 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-16 First Exploit
  • 2024-10-14 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
<= 0.11
Search vendor "Notmuchmail" for product "Notmuch" and version " <= 0.11"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.1
Search vendor "Notmuchmail" for product "Notmuch" and version "0.1"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.1.1
Search vendor "Notmuchmail" for product "Notmuch" and version "0.1.1"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.2
Search vendor "Notmuchmail" for product "Notmuch" and version "0.2"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.3
Search vendor "Notmuchmail" for product "Notmuch" and version "0.3"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.3.1
Search vendor "Notmuchmail" for product "Notmuch" and version "0.3.1"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.4
Search vendor "Notmuchmail" for product "Notmuch" and version "0.4"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.5
Search vendor "Notmuchmail" for product "Notmuch" and version "0.5"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.6
Search vendor "Notmuchmail" for product "Notmuch" and version "0.6"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.6
Search vendor "Notmuchmail" for product "Notmuch" and version "0.6"
254
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.6
Search vendor "Notmuchmail" for product "Notmuch" and version "0.6"
rc1
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.6.1
Search vendor "Notmuchmail" for product "Notmuch" and version "0.6.1"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.7
Search vendor "Notmuchmail" for product "Notmuch" and version "0.7"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.7
Search vendor "Notmuchmail" for product "Notmuch" and version "0.7"
rc1
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.8
Search vendor "Notmuchmail" for product "Notmuch" and version "0.8"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.8
Search vendor "Notmuchmail" for product "Notmuch" and version "0.8"
rc0
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.8
Search vendor "Notmuchmail" for product "Notmuch" and version "0.8"
rc1
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.9
Search vendor "Notmuchmail" for product "Notmuch" and version "0.9"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.9
Search vendor "Notmuchmail" for product "Notmuch" and version "0.9"
rc1
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.9
Search vendor "Notmuchmail" for product "Notmuch" and version "0.9"
rc2
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.10
Search vendor "Notmuchmail" for product "Notmuch" and version "0.10"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.10
Search vendor "Notmuchmail" for product "Notmuch" and version "0.10"
rc1
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.10
Search vendor "Notmuchmail" for product "Notmuch" and version "0.10"
rc2
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.10.1
Search vendor "Notmuchmail" for product "Notmuch" and version "0.10.1"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.10.2
Search vendor "Notmuchmail" for product "Notmuch" and version "0.10.2"
-
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.11
Search vendor "Notmuchmail" for product "Notmuch" and version "0.11"
rc1
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.11
Search vendor "Notmuchmail" for product "Notmuch" and version "0.11"
rc2
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.11
Search vendor "Notmuchmail" for product "Notmuch" and version "0.11"
rc2-1
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.11
Search vendor "Notmuchmail" for product "Notmuch" and version "0.11"
rc3
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe
Notmuchmail
Search vendor "Notmuchmail"
Notmuch
Search vendor "Notmuchmail" for product "Notmuch"
0.11
Search vendor "Notmuchmail" for product "Notmuch" and version "0.11"
rc3-1
Affected
in Gnu
Search vendor "Gnu"
Emacs
Search vendor "Gnu" for product "Emacs"
--
Safe