sympa CVE 脆弱性と CVE 一覧(13)

製品(CPE): — CVE 件数: 13

sympa 脆弱性概要

sympa 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

一般的な弱点パターンには パス処理の欠陥、vendor risk open redirect, and vendor risk input validation があり、vendor surface production workloads and vendor surface software deployment の利用場面で ファイル上書き and vendor impact unexpected behavior などのリスクが生じる可能性があります。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 113 / 13 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2021-46900 Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protection mechanism. [email protected] 7.5 0.07% 2023-12-31 2025-04-17
CVE-2020-29668 Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun. [email protected] 3.7 1.04% 2020-12-10 2024-11-21
CVE-2020-26932 debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group) [email protected] 4.3 0.15% 2020-10-10 2024-11-21
CVE-2020-26880 Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable. [email protected] 7.8 0.04% 2020-10-07 2024-11-21
CVE-2020-10936 Sympa before 6.2.56 allows privilege escalation. [email protected] 7.8 0.10% 2020-05-27 2024-11-21
CVE-2020-9369 Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters. [email protected] 7.5 2.12% 2020-02-24 2024-11-21
CVE-2018-1000671 sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be exploitable via Victim's browser must follow a URL supplied by the attacker. This vulnerability appears to have been fixed in none available. [email protected] 6.1 0.62% 2018-09-06 2024-11-21
CVE-2018-1000550 The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to be exploitable via HTTP GET/POST request. This vulnerability appears to have been fixed in 6.2.32. [email protected] 9.8 0.45% 2018-06-26 2024-11-21
CVE-2015-1306 The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors. [email protected] 5.0 0.61% 2015-01-22 2026-05-06
CVE-2012-2352 The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) do_arc_download, or (3) do_arc_delete functions. [email protected] 7.5 1.25% 2012-05-31 2026-04-29
CVE-2008-4476 sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sympa_aliases.$$ temporary file. NOTE: wwsympa.fcgi was also reported, but the issue occurred in a dead function, so it is not a vulnerability. [email protected] 6.9 0.04% 2008-10-07 2026-04-23
CVE-2008-1648 Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed value of the Content-Type header and unspecified other headers. NOTE: some of these details are obtained from third party information. [email protected] 5.0 2.25% 2008-04-02 2026-04-23
CVE-2004-1735 Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field. [email protected] 4.3 3.93% 2004-08-21 2026-04-16
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence