← Back

Mailman

mailman

Vendor: Gnu • 47 CVEs

CVEs (47)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gnu
1Mailman
Apr 16, 2026
Jun 18, 2002
N/A· v4
N/A· v3
2.1 LOW· v2
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
1Gnu
1Mailman
Apr 16, 2026
Jun 18, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries.
1Gnu
1Mailman
Apr 16, 2026
Dec 21, 2001
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.
1Gnu
1Mailman
Apr 16, 2026
Sep 5, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during auth...Show more
Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication.Show less
1Gnu
1Mailman
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.
1Gnu
1Mailman
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.
3Conectiva
GnuRedhat
3Linux
LinuxMailman
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.