Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.
https://exchange.xforce.ibmcloud.com/vulnerabilities/5326
https://euvd.enisa.europa.eu/vulnerability/EUVD-2000-0917
http://www.securityfocus.com/bid/1738
http://archives.neohapsis.com/archives/bugtraq/2000-10/0436.html
http://archives.neohapsis.com/archives/bugtraq/2000-10/0039.html