Vulnerabilities > GNU > Mailman > 2.0.9

DATE CVE VULNERABILITY TITLE RISK
2018-07-12 CVE-2018-13796 Improper Input Validation vulnerability in GNU Mailman
An issue was discovered in GNU Mailman before 2.1.28.
network
low complexity
gnu CWE-20
6.5
2015-04-13 CVE-2015-2775 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a ..
network
high complexity
canonical debian redhat gnu CWE-22
7.6
2006-09-07 CVE-2006-4624 Code Injection vulnerability in GNU Mailman
CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.
network
high complexity
gnu CWE-94
2.6
2006-03-31 CVE-2006-0052 Denial Of Service vulnerability in GNU Mailman Attachment Scrubber Malformed MIME Message
The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.
network
low complexity
gnu
5.0
2005-11-16 CVE-2005-3573 Denial Of Service vulnerability in GNU Mailman Attachment Scrubber UTF8 Filename
Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments, which allows remote attackers to cause a denial of service (application crash).
network
low complexity
gnu
5.0
2005-01-10 CVE-2004-1177 Unspecified vulnerability in GNU Mailman
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
network
gnu
4.3
2004-12-31 CVE-2004-1143 Unspecified vulnerability in GNU Mailman
The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
network
low complexity
gnu
7.5
2004-06-01 CVE-2004-0182 Unspecified vulnerability in GNU Mailman
Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.
network
low complexity
gnu
5.0
2004-03-03 CVE-2003-0991 Remote Denial Of Service vulnerability in GNU Mailman Malformed Message
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.
network
low complexity
gnu sgi
5.0
2004-02-17 CVE-2003-0992 Unspecified vulnerability in GNU Mailman
Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.
network
gnu
4.3