← Back

Pine

pine

Vendor: University Of Washington • 15 CVEs

CVEs (15)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1University Of Washington
1Pine
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
1.2 LOW· v2
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.
1University Of Washington
1Pine
Apr 16, 2026
Sep 17, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.
8Microsoft
MozillaMutt+5 more
8Balsa
EudoraEvolution+5 more
Apr 16, 2026
Jun 16, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
1University Of Washington
3C Client
Imap 2002bPine
Apr 16, 2026
Jun 16, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size...Show more
c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.Show less
1University Of Washington
1Pine
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.8 HIGH· v2
The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with...Show more
The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field.Show less
1University Of Washington
1Pine
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Pine 4.2.1 through 4.4.4 puts Unix usernames and/or uid into Sender: and X-Sender: headers, which could allow remote attackers to obtain sensitive information.
1University Of Washington
1Pine
Apr 16, 2026
Dec 11, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").
1University Of Washington
1Pine
Apr 16, 2026
Jul 26, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).
5Engardelinux
ImmunixMandrakesoft+2 more
6Immunix
LinuxMandrake Linux+3 more
Apr 16, 2026
Oct 18, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.
1University Of Washington
1Pine
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.
1University Of Washington
2Imap
Pine
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in University of Washington c-client library (used by pine and other programs) allows remote attackers to execute arbitrary commands via a long X-Keywords header.
1University Of Washington
1Pine
Apr 16, 2026
Nov 18, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.
1University Of Washington
1Pine
Apr 16, 2026
Jun 28, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.
3Hp
ScoUniversity Of Washington
3Dtmail
PineUnixware
Apr 16, 2026
Dec 16, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.
3Freebsd
SlackwareUniversity Of Washington
3Freebsd
PineSlackware Linux
Apr 16, 2026
Aug 26, 1996
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.