VYPR

Mailman

by GNU

pypi: mailman

Source repositories

CVEs (47)

  • CVE-2003-0965Feb 17, 2004
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.

  • CVE-2002-0389Jun 18, 2002
    risk 0.00cvss epss 0.00

    Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.

  • CVE-2001-0884Dec 21, 2001
    risk 0.00cvss epss 0.02

    Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.

  • CVE-2001-1132Sep 5, 2001
    risk 0.00cvss epss 0.03

    Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication.

  • CVE-2001-0290May 3, 2001
    risk 0.00cvss epss 0.00

    Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.

  • CVE-2000-0861Nov 14, 2000
    risk 0.00cvss epss 0.01

    Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.

  • CVE-2000-0701Oct 20, 2000
    risk 0.00cvss epss 0.00

    The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.

Page 3 of 3