cbcvebase.

Gnu Mailman vulnerabilities

47 known vulnerabilities affecting gnu/mailman.

Total CVEs
47
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
HIGH14MEDIUM30LOW3

Vulnerabilities

Page 3 of 3
CVE-2006-4624P4LOWCVSS 2.6≤ 2.1.82006-09-07
CVE-2006-4624 [LOW] CWE-94 CVE-2006-4624: CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.
nvd
CVE-2004-0182P4MEDIUMCVSS 5.0≤ 2.0.122004-06-01
CVE-2004-0182 [MEDIUM] CVE-2004-0182: Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email mess Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.
nvd
CVE-2003-0992P4MEDIUMCVSS 4.3≤ 2.1.32004-02-17
CVE-2003-0992 [MEDIUM] CVE-2003-0992: Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows re Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.
nvd
CVE-2000-0701P4MEDIUMCVSS 4.6v2.02000-10-20
CVE-2000-0701 [MEDIUM] CVE-2000-0701: The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format stri The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.
nvd
CVE-2010-3089P4LOWCVSS 3.5≤ 2.1.13v2.1+13 more2010-09-15
CVE-2010-3089 [LOW] CWE-79 CVE-2010-3089: Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote aut Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.
nvd
CVE-2006-1712P4LOWCVSS 2.6v2.1.72006-04-11
CVE-2006-1712 [LOW] CVE-2006-1712: Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2 Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.
nvd
CVE-2001-0290P4MEDIUMCVSS 4.6≤ 2.0.22001-05-03
CVE-2001-0290 [MEDIUM] CVE-2001-0290: Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords. Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.
nvd
Gnu Mailman vulnerabilities | cvebase