Vulnerabilities (CVE)

Filtered by vendor Gnu Subscribe
Filtered by product Mailman
Total 47 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0389 1 Gnu 1 Mailman 2016-12-28 2.1 LOW N/A
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
CVE-2015-2775 4 Canonical, Debian, Gnu and 1 more 4 Ubuntu Linux, Debian Linux, Mailman and 1 more 2016-12-24 7.6 HIGH N/A
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
CVE-2005-0080 2 Gnu, Ubuntu 2 Mailman, Ubuntu Linux 2016-10-18 5.0 MEDIUM N/A
The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.
CVE-2002-0388 1 Gnu 1 Mailman 2009-07-21 7.5 HIGH N/A
Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries.
CVE-2004-0182 1 Gnu 1 Mailman 2008-09-05 5.0 MEDIUM N/A
Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.
CVE-2002-0855 1 Gnu 1 Mailman 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.
CVE-2001-0290 1 Gnu 1 Mailman 2008-09-05 4.6 MEDIUM N/A
Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.