CVE-2017-17689: 9folders Nine

Medium severity, CVSS 5.9. EPSS: 4.1% chance of exploitation in the next 30 days.

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

Affected products

  • 9folders Nine: affected versions not specified
  • Apple Mail: affected versions not specified
  • Bloop Airmail: affected versions not specified
  • Emclient Emclient: affected versions not specified
  • Flipdogsolutions Maildroid: affected versions not specified
  • Freron Mailmate: affected versions not specified
  • Gnome Evolution: affected versions not specified
  • Google Gmail: affected versions not specified
  • Horde Horde Imp: affected versions not specified
  • IBM Notes: affected versions not specified
  • Kde Kmail: affected versions not specified
  • Kde Trojita: affected versions not specified
  • Microsoft Outlook: version 2007 only; version 2010 only; version 2013 only; version 2016 only
  • Mozilla Thunderbird: affected versions not specified
  • Postbox-Inc Postbox: affected versions not specified
  • r2mail2 r2mail2: affected versions not specified
  • Ritlabs The Bat: affected versions not specified

Published 2018-05-16. Last modified 2026-06-17.