Products: 1
    Vulnerabilities: 13
    Known Exploited: 0
    1
    Critical Level Threats
    5
    High Level Threats
    6
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-46900

    Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protection mechanism.

    Last Modified: Apr 17, 2025
    Published: Dec 31, 2023

    CVE-2020-29668

    Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.

    Last Modified: Nov 21, 2024
    Published: Dec 10, 2020

    CVE-2020-26932

    debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)

    Last Modified: Nov 21, 2024
    Published: Oct 10, 2020

    CVE-2020-26880

    Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.

    Last Modified: Nov 21, 2024
    Published: Oct 07, 2020

    CVE-2020-10936

    Sympa before 6.2.56 allows privilege escalation.

    Last Modified: Nov 21, 2024
    Published: May 27, 2020
    Items Per Page