Back

CVE-2003-0167

Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.

Published: Apr 2, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (9)

Vendor Product Version
mutt mutt 1.3.12
mutt mutt 1.3.12.1
mutt mutt 1.3.16
mutt mutt 1.3.17
mutt mutt 1.3.22
mutt mutt 1.3.24
mutt mutt 1.3.25
mutt mutt 1.3.27
mutt mutt 1.3.28

GitHub Security Advisory GHSA-v7m5-jjhm-hp24

Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.54%

Top 17% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub