CVE-2021-37746
Published Jul 30, 2021textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
Vendor/product archive
2 CVEs tagged to sylpheed_project / sylpheed — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
libsylph/utils.c in Sylpheed through 3.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers t…