← Vulnerability feed

Vulnerability record · CVE-2004-0078 · published 3 March 2004

CVE-2004-0078: Mutt vulnerability

Mutt · Mutt

Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.

7.5 CVSS 2.0 High EPSS 5.4% · top 7.6%
7.5CVSS 2.0 base score
5.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-013.0.txt
http://bugs.debian.org/126336
http://marc.info/?l=bugtraq&m=107651677817933&w=2
http://marc.info/?l=bugtraq&m=107696262905039&w=2
http://marc.info/?l=bugtraq&m=107884956930903&w=2
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:010
http://www.osvdb.org/3918
http://www.redhat.com/support/errata/RHSA-2004-050.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2004-051.html PatchVendor Advisory
http://www.securityfocus.com/bid/9641 PatchVendor Advisory
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.405053
https://exchange.xforce.ibmcloud.com/vulnerabilities/15134
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A811
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A838
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-013.0.txt
http://bugs.debian.org/126336
http://marc.info/?l=bugtraq&m=107651677817933&w=2
http://marc.info/?l=bugtraq&m=107696262905039&w=2
http://marc.info/?l=bugtraq&m=107884956930903&w=2
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:010
http://www.osvdb.org/3918
http://www.redhat.com/support/errata/RHSA-2004-050.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2004-051.html PatchVendor Advisory
http://www.securityfocus.com/bid/9641 PatchVendor Advisory
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.405053
https://exchange.xforce.ibmcloud.com/vulnerabilities/15134
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A811
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A838

Track CVE-2004-0078 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-14349Debian linux improper input validation vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.EPSS 3.2%9.8CVE-2018-14350Mutt out-of-bounds write vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response wi…EPSS 5.0%9.8CVE-2018-14351Mutt improper input validation vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.EPSS 3.2%9.8CVE-2018-14352Mutt out-of-bounds write vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote character…EPSS 4.0%9.8CVE-2018-14353Mutt vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.EPSS 3.7%9.8CVE-2018-14354Mutt os command injection vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquo…EPSS 6.2%9.8CVE-2018-14356Debian linux vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.EPSS 3.2%9.8CVE-2018-14357Mutt os command injection vulnerabilityAn issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquo…EPSS 5.0%

Source: NIST National Vulnerability Database (record CVE-2004-0078), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.