Page 2 of 15 results (0.002 seconds)

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 0

14 Nov 2000 — Buffer overflow in University of Washington c-client library (used by pine and other programs) allows remote attackers to execute arbitrary commands via a long X-Keywords header. • http://archives.neohapsis.com/archives/bugtraq/2000-08/0425.html •

CVSS: 10.0EPSS: 2%CPEs: 2EXPL: 0

18 Nov 1999 — Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL. • ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-036.0.txt •

CVSS: 10.0EPSS: 0%CPEs: 4EXPL: 1

28 Jun 1999 — Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine. • http://www.novell.com/linux/security/advisories/pine_update_announcement.html •

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 0

16 Dec 1997 — MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook. Desbordamiento de buffer en clientes de correo, como Solaris mailtool y Outlook • https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-008 •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

26 Aug 1996 — Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail. • http://marc.info/?l=bugtraq&m=87602167419803&w=2 •