← Back

Sympa

sympa

13 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Sympa
sympa

CVEs (13)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sympa
1Sympa
Apr 17, 2025
Dec 31, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for store...Show more
Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protection mechanism.Show less
3Debian
FedoraprojectSympa
3Debian Linux
FedoraSympa
Nov 21, 2024
Dec 10, 2020
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
2Debian
Sympa
2Debian Linux
Sympa
Nov 21, 2024
Oct 10, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
3Debian
FedoraprojectSympa
3Debian Linux
FedoraSympa
Nov 21, 2024
Oct 7, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa...Show more
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraSympa+1 more
Nov 21, 2024
May 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Sympa before 6.2.56 allows privilege escalation.
3Debian
FedoraprojectSympa
3Debian Linux
FedoraSympa
Nov 21, 2024
Feb 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.
2Debian
Sympa
2Debian Linux
Sympa
Nov 21, 2024
Sep 6, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and re...Show more
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be exploitable via Victim's browser must follow a URL supplied by the attacker. This vulnerability appears to have been fixed in none available.Show less
2Debian
Sympa
2Debian Linux
Sympa
Nov 21, 2024
Jun 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server file...Show more
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to be exploitable via HTTP GET/POST request. This vulnerability appears to have been fixed in 6.2.32.Show less
1Sympa
1Sympa
May 6, 2026
Jan 22, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors.
1Sympa
1Sympa
Apr 29, 2026
May 31, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related t...Show more
The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) do_arc_download, or (3) do_arc_delete functions.Show less
1Sympa
1Sympa
Apr 23, 2026
Oct 7, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sympa_aliases.$$ temporary file. NOTE: wwsympa.fcgi was also reported, but the issue occurred in a dead function,...Show more
sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sympa_aliases.$$ temporary file. NOTE: wwsympa.fcgi was also reported, but the issue occurred in a dead function, so it is not a vulnerability.Show less
1Sympa
1Sympa
Apr 23, 2026
Apr 2, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed value of the Content-Type header and unspecified other headers. NOTE: some of these details are...Show more
Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed value of the Content-Type header and unspecified other headers. NOTE: some of these details are obtained from third party information.Show less
1Sympa
1Sympa
Apr 16, 2026
Aug 21, 2004
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.