Vulnerabilities
Vulnerable Software
Gnu:  >> Mailman  >> 2.0.4  Security Vulnerabilities
The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
CVSS Score
7.5
EPSS Score
0.009
Published
2004-12-31
Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.
CVSS Score
5.0
EPSS Score
0.006
Published
2004-06-01
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.
CVSS Score
5.0
EPSS Score
0.016
Published
2004-03-03
Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.
CVSS Score
6.8
EPSS Score
0.031
Published
2004-02-17
Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.
CVSS Score
4.3
EPSS Score
0.005
Published
2004-02-17
Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries.
CVSS Score
7.5
EPSS Score
0.031
Published
2002-06-18
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
CVSS Score
2.1
EPSS Score
0.001
Published
2002-06-18
Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.
CVSS Score
5.1
EPSS Score
0.007
Published
2001-12-21
Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication.
CVSS Score
7.5
EPSS Score
0.009
Published
2001-09-05


Contact Us

Shodan ® - All rights reserved