Tin is a narrowly scoped vendor with a minimal disclosed vulnerability footprint concentrated around its core product. The observed weakness classes are classified broadly and do not establish a clear pattern; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tin over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0804HIGH Off-by-one error in TIN 1.8.0 and earlier might allow attackers to execute arbitrary code via unknown vectors that trigger a buffer overflow. | Feb 21, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-6122HIGH Multiple buffer overflows in TIN before 1.8.2 have unspecified impact and attack vectors, a different vulnerability than CVE-2006-0804. | Nov 26, 2006 | 7.5 | 19 | NO | NO |
CVE-1999-1091MEDIUM UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by th | Jan 15, 2002 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tin.
Media articles that mention a CVE ID that affects a product developed by Tin — matched by CVE ID, not by vendor name.