Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Mailman
(Gnu)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 47 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2004-03-03 | CVE-2003-0991 | Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands. | Mailman, Propack | N/A | ||
2004-02-17 | CVE-2003-0965 | Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities. | Mailman | N/A | ||
2003-02-07 | CVE-2003-0038 | Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters. | Mailman | N/A | ||
2002-09-05 | CVE-2002-0855 | Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature. | Mailman | N/A | ||
2002-06-18 | CVE-2002-0389 | Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives. | Mailman | N/A | ||
2002-06-18 | CVE-2002-0388 | Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries. | Mailman | N/A | ||
2001-09-05 | CVE-2001-1132 | Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication. | Mailman | N/A | ||
2001-12-21 | CVE-2001-0884 | Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users. | Mailman | N/A | ||
2001-05-03 | CVE-2001-0290 | Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords. | Mailman | N/A | ||
2000-11-14 | CVE-2000-0861 | Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion. | Mailman | N/A |