Gnu Mailman vulnerabilities

46 known vulnerabilities affecting gnu/mailman.

Total CVEs
46
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
HIGH14MEDIUM29LOW3

Vulnerabilities

Page 3 of 3
CVE-2002-0388HIGHCVSS 7.5PoC≤ 2.0.112002-06-18
CVE-2002-0388 [HIGH] CVE-2002-0388: Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute scri Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries.
nvd
CVE-2001-0884MEDIUMCVSS 5.1v5.0v5.1+2 more2001-12-21
CVE-2001-0884 [MEDIUM] CVE-2001-0884: Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.
nvd
CVE-2001-1132HIGHCVSS 7.5≤ 2.0.52001-09-05
CVE-2001-1132 [HIGH] CVE-2001-1132: Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication.
nvd
CVE-2001-0290MEDIUMCVSS 4.6≤ 2.0.22001-05-03
CVE-2001-0290 [MEDIUM] CVE-2001-0290: Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords. Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.
nvd
CVE-2000-0861HIGHCVSS 7.2v1.12000-11-14
CVE-2000-0861 [HIGH] CVE-2000-0861: Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.
nvd
CVE-2000-0701MEDIUMCVSS 4.6v2.02000-10-20
CVE-2000-0701 [MEDIUM] CVE-2000-0701: The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format stri The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.
nvd