Gnu

Mailman

47 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a gi...

  • EPSS 1.59%
  • Published 10.01.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

  • EPSS 0.91%
  • Published 31.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.

  • EPSS 2.64%
  • Published 18.08.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.

  • EPSS 0.57%
  • Published 01.06.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.

  • EPSS 1.58%
  • Published 03.03.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.

  • EPSS 0.55%
  • Published 17.02.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.

  • EPSS 3.14%
  • Published 17.02.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.

  • EPSS 10.63%
  • Published 07.02.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.

Exploit
  • EPSS 41.04%
  • Published 05.09.2002 04:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.