Enigmail

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    0
    Critical Level Threats
    7
    High Level Threats
    7
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-14664

    In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, he unknowingly leaks the plaintext of the encrypted message part(s) back to the attacker. This attack variant bypasses protection mechanisms implemented after the "EFAIL" attacks.

    Last Modified: Nov 21, 2024
    Published: Aug 05, 2019

    CVE-2019-12269

    Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.

    Last Modified: Nov 21, 2024
    Published: May 21, 2019

    CVE-2018-15586

    Enigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages using a PGP/INLINE signature wrapped within a specially crafted multipart HTML email.

    Last Modified: Nov 21, 2024
    Published: Feb 11, 2019

    CVE-2018-12019

    The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote attackers to spoof arbitrary email signatures via public keys containing crafted primary user ids.

    Last Modified: Nov 21, 2024
    Published: Jun 13, 2018

    CVE-2017-17844

    An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacker cannot directly decrypt) to a victim, and relying on the victim to automatically decrypt that block and then send it back to the attacker as quoted text, aka the TBE-01-005 "replay" issue.

    Last Modified: Apr 20, 2025
    Published: Dec 22, 2017
    Items Per Page
    Enigmail Vulnerabilities & Security CVEs | CVE-DB