VendorsUniversity Of Washingtonpineall versions
Vulnerabilities

University Of Washington Pine

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2000-0353
Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.
Published 2000-07-12 · Modified
10.0EPSS 0.038
CVE-2000-0352
Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.
Published 2000-07-12 · Modified
10.0EPSS 0.035
CVE-2002-2325
The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field.
Published 2007-10-26 · Modified
7.81 PoCEPSS 0.035
CVE-2003-0720
Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.
Published 2003-09-12 · Modified
7.51 PoCEPSS 0.129
CVE-2000-0909
Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.
Published 2001-01-22 · Modified
7.51 PoCEPSS 0.115
CVE-2003-0297
c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.
Published 2003-05-15 · Modified
7.5EPSS 0.027
CVE-2000-0847
Buffer overflow in University of Washington c-client library (used by pine and other programs) allows remote attackers to execute arbitrary commands via a long X-Keywords header.
Published 2001-01-22 · Modified
7.5EPSS 0.025
CVE-2002-0014
URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).
Published 2003-04-02 · Modified
7.5EPSS 0.022
CVE-2002-1320
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").
Published 2004-09-01 · Modified
5.01 PoCEPSS 0.096
CVE-2003-0300
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
Published 2003-05-15 · Modified
5.0EPSS 0.034
CVE-1999-0004
MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.
Published 2000-02-04 · Modified
5.0EPSS 0.028
CVE-2002-1903
Pine 4.2.1 through 4.4.4 puts Unix usernames and/or uid into Sender: and X-Sender: headers, which could allow remote attackers to obtain sensitive information.
Published 2005-06-28 · Modified
5.0EPSS 0.014
CVE-1999-1187
Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.
Published 2001-09-12 · Modified
4.6EPSS 0.003
CVE-2001-0736
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.
Published 2001-10-12 · Modified
2.11 PoCEPSS 0.008
CVE-2005-1066
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.
Published 2005-04-12 · Modified
1.2EPSS 0.003