CVE-2004-1143
https://notcve.org/view.php?id=CVE-2004-1143
The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286796 http://marc.info/?l=bugtraq&m=110549296126351&w=2 http://secunia.com/advisories/13603 http://www.novell.com/linux/security/advisories/2005_07_mailman.html https://exchange.xforce.ibmcloud.com/vulnerabilities/18857 •
CVE-2004-0412
https://notcve.org/view.php?id=CVE-2004-0412
Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server. Mailman anteriores a 2.1.5 permiten a atacantes remotos obtener contraseñas de usuario mediante peticiones de correo electronico especialmente elaboradas. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000842 http://mail.python.org/pipermail/mailman-announce/2004-May/000072.html http://marc.info/?l=bugtraq&m=109034869927955&w=2 http://secunia.com/advisories/11701 http://security.gentoo.org/glsa/glsa-200406-04.xml http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:051 http://www.securityfocus.com/bid/10412 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=123559 https://exchange.xforce.ibmcloud •
CVE-2004-0182
https://notcve.org/view.php?id=CVE-2004-0182
Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field. • ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc http://www.redhat.com/support/errata/RHSA-2004-156.html https://access.redhat.com/security/cve/CVE-2004-0182 https://bugzilla.redhat.com/show_bug.cgi?id=1617173 •
CVE-2003-0991
https://notcve.org/view.php?id=CVE-2003-0991
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands. Vulnerabilidad desconocida en el manejador de instrucciones por correo en Mailman anteriores a 2.0.14 permite a atacantes remotos causar una denegación de servicio (caída) mediante instrucciones de correo electrónico malformadas. • ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000842 http://mail.python.org/pipermail/mailman-announce/2004-February/000067.html http://www.debian.org/security/2004/dsa-436 http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:013 http://www.redhat.com/support/errata/RHSA-2004-019.html http://www.securityfocus.com/bid/9620 https://exchange.xforce.ibmcloud.com/vulnerabilities/15106 https:/ •
CVE-2003-0965
https://notcve.org/view.php?id=CVE-2003-0965
Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Mailman anteriores a 2.1.4 permite a atacantes remotos robar cookies de sesión y llevar a cabo actividades no autorizadas. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000842 http://mail.python.org/pipermail/mailman-announce/2003-December/000066.html http://secunia.com/advisories/10519 http://www.debian.org/security/2004/dsa-436 http://www.mandriva.com/security/advisories?name=MDKSA-2004:013 http://www.osvdb.org/3305 http://www.redhat.com/support/errata/RHSA-2004-020.html http://www.securityfocus.com/bid/9336 https://exchange.xforce.ibmcloud.com/vulnerabilities/14121 https://oval.ci •