Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.
https://www.enigmail.net/index.php/en/download/changelog
https://sourceforge.net/p/enigmail/bugs/983/
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00061.html