CVE-2014-2576: Claws-Mail
Medium severity, CVSS 6.8. EPSS: 2% chance of exploitation in the next 30 days.
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Affected products
- Claws-Mail Claws-Mail: up to and including 3.9.3
- Opensuse Opensuse: version 12.3 only; version 13.1 only
Published 2014-10-15. Last modified 2026-06-17.