Known Vulnerabilities for Mailman by Gnu
Listed below are 10 of the newest known vulnerabilities associated with "Mailman" by "Gnu".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-43332 | In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list ad... | 6.5 - MEDIUM | 2021-11-12 | 2023-11-07 |
| CVE-2021-43331 | In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS. | 6.1 - MEDIUM | 2021-11-12 | 2023-11-07 |
| CVE-2021-42097 | GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account.... | 8 - HIGH | 2021-10-21 | 2023-11-07 |
| CVE-2021-42096 | GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin passwor... | 4.3 - MEDIUM | 2021-10-21 | 2023-11-07 |
| CVE-2021-34337 | An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to det... | 6.3 - MEDIUM | 2023-04-15 | 2023-04-25 |
| CVE-2020-15011 | GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page. | 4.3 - MEDIUM | 2020-06-24 | 2021-11-30 |
| CVE-2020-12137 | GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may con... | 6.1 - MEDIUM | 2020-04-24 | 2023-11-07 |
| CVE-2020-12108 | /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection. | 6.5 - MEDIUM | 2020-05-06 | 2023-11-07 |
| CVE-2018-5950 | Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary w... | 6.1 - MEDIUM | 2018-01-23 | 2023-11-07 |
| CVE-2018-0618 | Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary we... | 5.4 - MEDIUM | 2018-07-26 | 2020-05-06 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Mailman | 2.1b1 | All | All | All |
| Application | Gnu | Mailman | 2.1.9 | All | All | All |
| Application | Gnu | Mailman | 2.1.8 | All | All | All |
| Application | Gnu | Mailman | 2.1.7 | All | All | All |
| Application | Gnu | Mailman | 2.1.6 | All | All | All |
| Application | Gnu | Mailman | 2.1.5.8 | All | All | All |
| Application | Gnu | Mailman | 2.1.5 | All | All | All |
| Application | Gnu | Mailman | 2.1.4 | All | All | All |
| Application | Gnu | Mailman | 2.1.33 | All | All | All |
| Application | Gnu | Mailman | 2.1.31 | All | All | All |
| Application | Gnu | Mailman | 2.1.30 | All | All | All |
| Application | Gnu | Mailman | 2.1.3 | All | All | All |
| Application | Gnu | Mailman | 2.1.29 | All | All | All |
| Application | Gnu | Mailman | 2.1.28 | All | All | All |
| Application | Gnu | Mailman | 2.1.27 | All | All | All |
| Application | Gnu | Mailman | 2.1.26 | All | All | All |
| Application | Gnu | Mailman | 2.1.25 | All | All | All |
| Application | Gnu | Mailman | 2.1.24 | All | All | All |
| Application | Gnu | Mailman | 2.1.23 | All | All | All |
| Application | Gnu | Mailman | 2.1.22 | All | All | All |