CVE-2019-12269: Enigmail
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.
Affected products
- Enigmail Enigmail: before 2.0.11 (fixed in 2.0.11)
Published 2019-05-21. Last modified 2026-06-17.