Vulnerabilities > Great Circle Associates > Majordomo > 1.94.4

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1367 Configuration vulnerability in Great Circle Associates Majordomo 1.94.4/1.94.5
The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command.
network
low complexity
great-circle-associates CWE-16
7.8
1999-12-28 CVE-2000-0037 Unspecified vulnerability in Great Circle Associates Majordomo 1.94.4/1.94.5
Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.
local
low complexity
great-circle-associates
4.6