VendorsDavid Harrispegasus_mailall versions
Vulnerabilities

David Harris Pegasus Mail

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2002-1075
Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers.
Published 2002-08-31 · Modified
7.51 PoCEPSS 0.057
CVE-2000-0931
Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data.
Published 2000-11-29 · Modified
7.5EPSS 0.020
CVE-2005-4444
Stack-based buffer overflow in the trace message functionality in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allow remote attackers to execute arbitrary code via a long POP3 reply.
Published 2005-12-21 · Modified
5.1EPSS 0.032
CVE-2005-4445
Off-by-one error in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allows remote attackers to execute arbitrary code via a long email message header, which triggers a one-byte buffer overflow.
Published 2005-12-21 · Modified
5.1EPSS 0.031
CVE-2000-0930
Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.
Published 2001-01-22 · Modified
5.01 PoCEPSS 0.077
CVE-1999-1366
Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.
Published 2001-09-12 · Modified
3.6EPSS 0.002