3 results (0.004 seconds)

CVSS: 5.5EPSS: 0%CPEs: 44EXPL: 2

31 Dec 2003 — Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read other users' email messages. • http://securitytracker.com/id?1008004 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

20 Sep 2001 — Directory traversal vulnerability in Rit Research Labs The Bat! 1.48f and earlier allows a remote attacker to create arbitrary files via a "dot dot" attack in the filename for an attachment. • http://www.securityfocus.com/archive/1/154359 •

CVSS: 9.8EPSS: 0%CPEs: 40EXPL: 1

24 May 2001 — The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! to misrepresent the attachment's type with a different icon. • http://archives.neohapsis.com/archives/bugtraq/2001-04/0013.html •