Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2008-4476

Disclosure Date: October 07, 2008 (last updated October 04, 2023)
sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sympa_aliases.$$ temporary file. NOTE: wwsympa.fcgi was also reported, but the issue occurred in a dead function, so it is not a vulnerability.
0
Attacker Value
Unknown

CVE-2008-1648

Disclosure Date: April 02, 2008 (last updated October 04, 2023)
Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed value of the Content-Type header and unspecified other headers. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2005-0073

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-1735

Disclosure Date: August 21, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.
0