Skip to main content

Vendor archive

university_of_washington CVEs

Beta · best-effort

28 CVEs tagged to vendor university_of_washington4 Critical, 11 High, 9 Medium, 4 Low, 0 Unrated.

CVE-2008-5514

Published Dec 23, 2008

Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5006

Published Nov 10, 2008

smtp.c in the c-client library in University of Washington IMAP Toolkit 2007b allows remote SMTP servers to cause a denial of service (NULL pointer dereference and application cra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1392

Published Mar 26, 2006

Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1393

Published Mar 26, 2006

Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 befor…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1394

Published Mar 26, 2006

Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 befor…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2933

Published Oct 13, 2005

Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0198

Published May 2, 2005

A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does no…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1066

Published May 2, 2005

Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0720

Published Sep 17, 2003

Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1782

Published Dec 31, 2002

The default configuration of University of Washington IMAP daemon (wu-imapd), when running on a system that does not allow shell access, allows a local user with a valid IMAP acco…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1903

Published Dec 31, 2002

Pine 4.2.1 through 4.4.4 puts Unix usernames and/or uid into Sender: and X-Sender: headers, which could allow remote attackers to obtain sensitive information.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2325

Published Dec 31, 2002

The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (cli…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1320

Published Dec 11, 2002

Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of q…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0014

Published Jul 26, 2002

URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0379

Published Jun 25, 2002

Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001.315) with legacy RFC 1730 support, and imapd 2000.287 and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0691

Published Sep 20, 2001

Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1197

Published Aug 31, 2001

POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0909

Published Dec 19, 2000

Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0284

Published Apr 16, 2000

Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 28 CVEsPage 1 of 2