← Back

Majordomo

majordomo

Vendor: Great Circle Associates • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Great Circle Associates
1Majordomo
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
7.8 HIGH· v2
The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "whi...Show more
The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command.Show less
1Great Circle Associates
1Majordomo
Apr 16, 2026
Dec 28, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.
1Great Circle Associates
1Majordomo
Apr 16, 2026
Dec 28, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
resend command in Majordomo allows local users to gain privileges via shell metacharacters.
1Great Circle Associates
1Majordomo
Apr 16, 2026
Aug 24, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.
1Great Circle Associates
1Majordomo
Apr 16, 2026
Jun 9, 1994
N/A· v4
N/A· v3
7.5 HIGH· v2
Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.