Vulnerabilities > Sympa > Sympa > 4.0.b2

DATE CVE VULNERABILITY TITLE RISK
2023-12-31 CVE-2021-46900 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Sympa
Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value.
network
low complexity
sympa CWE-327
7.5
2020-12-10 CVE-2020-29668 Reliance on Cookies without Validation and Integrity Checking vulnerability in multiple products
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
network
high complexity
sympa fedoraproject debian CWE-565
3.7
2020-10-10 CVE-2020-26932 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
network
low complexity
sympa debian CWE-732
4.3
2020-10-07 CVE-2020-26880 Improper Privilege Management vulnerability in multiple products
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.
local
low complexity
sympa fedoraproject debian CWE-269
7.8
2020-05-27 CVE-2020-10936 Improper Privilege Management vulnerability in multiple products
Sympa before 6.2.56 allows privilege escalation.
local
low complexity
sympa fedoraproject debian canonical CWE-269
7.8
2018-06-26 CVE-2018-1000550 Path Traversal vulnerability in multiple products
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem.
network
low complexity
sympa debian CWE-22
7.5
2012-05-31 CVE-2012-2352 Permissions, Privileges, and Access Controls vulnerability in Sympa
The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) do_arc_download, or (3) do_arc_delete functions.
network
low complexity
sympa CWE-264
7.5
2008-04-02 CVE-2008-1648 Improper Input Validation vulnerability in Sympa
Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed value of the Content-Type header and unspecified other headers.
network
low complexity
sympa CWE-20
5.0