Show filters
54 Total Results
Displaying 11-20 of 54
Sort by:
Attacker Value
Unknown

CVE-2019-3693

Disclosure Date: January 24, 2020 (last updated February 21, 2025)
A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1 allowed local attackers to escalate their privileges from user wwwrun to root. Additionally arbitrary files could be changed to group mailman. This issue affects: SUSE Linux Enterprise Server 11 mailman versions prior to 2.1.15-9.6.15.1. SUSE Linux Enterprise Server 12 mailman versions prior to 2.1.17-3.11.1. openSUSE Leap 15.1 mailman version 2.1.29-lp151.2.14 and prior versions.
Attacker Value
Unknown

CVE-2018-0618

Disclosure Date: July 26, 2018 (last updated November 27, 2024)
Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2018-13796

Disclosure Date: July 12, 2018 (last updated November 08, 2023)
An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.
0
Attacker Value
Unknown

CVE-2018-5950

Disclosure Date: January 23, 2018 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.
Attacker Value
Unknown

CVE-2016-6893

Disclosure Date: September 02, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as demonstrated by gaining access to the credentials of a victim's account.
0
Attacker Value
Unknown

CVE-2016-7123

Disclosure Date: September 02, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
0
Attacker Value
Unknown

CVE-2015-2775

Disclosure Date: April 13, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
0
Attacker Value
Unknown

CVE-2011-5024

Disclosure Date: December 29, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in mmsearch/design in the Mailman/htdig integration patch for Mailman allows remote attackers to inject arbitrary web script or HTML via the config parameter.
0
Attacker Value
Unknown

CVE-2011-0707

Disclosure Date: February 22, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.
0
Attacker Value
Unknown

CVE-2010-3089

Disclosure Date: September 15, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.
0