Mailman
by Mailman
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2003-0992 | 0.00 | — | 0.01 | Feb 17, 2004 | Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users. | |||
| CVE-2002-0389 | 0.00 | — | 0.00 | Jun 18, 2002 | Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives. | |||
| CVE-2001-0884 | 0.00 | — | 0.02 | Dec 21, 2001 | Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users. | |||
| CVE-2001-1132 | 0.00 | — | 0.03 | Sep 5, 2001 | Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication. | |||
| CVE-2001-0290 | 0.00 | — | 0.00 | May 3, 2001 | Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords. | |||
| CVE-2000-0861 | 0.00 | — | 0.01 | Nov 14, 2000 | Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion. |
- CVE-2003-0992Feb 17, 2004risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.
- CVE-2002-0389Jun 18, 2002risk 0.00cvss —epss 0.00
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
- CVE-2001-0884Dec 21, 2001risk 0.00cvss —epss 0.02
Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.
- CVE-2001-1132Sep 5, 2001risk 0.00cvss —epss 0.03
Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication.
- CVE-2001-0290May 3, 2001risk 0.00cvss —epss 0.00
Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.
- CVE-2000-0861Nov 14, 2000risk 0.00cvss —epss 0.01
Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.
Page 2 of 2