VYPR

PINE

by PINE

CVEs (5)

  • CVE-2000-0909Dec 19, 2000
    risk 0.04cvss —epss 0.12

    Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.

  • CVE-2001-0736Oct 18, 2001
    risk 0.03cvss —epss 0.01

    Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.

  • CVE-2003-0721Sep 17, 2003
    risk 0.00cvss —epss 0.04

    Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.

  • CVE-2002-0014Jul 26, 2002
    risk 0.00cvss —epss 0.02

    URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).

  • CVE-2000-0352Nov 18, 1999
    risk 0.00cvss —epss 0.03

    Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.