Количество 10
Количество 10
CVE-2020-12137
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
CVE-2020-12137
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
CVE-2020-12137
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
CVE-2020-12137
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed app ...
SUSE-SU-2020:14356-1
Security update for mailman
GHSA-7mvx-jp9h-p8gh
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.
ELSA-2020-4667
ELSA-2020-4667: mailman:2.1 security and bug fix update (MODERATE)
BDU:2020-03997
Уязвимость программного обеспечения для управления рассылками электронных писем Mailman, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных
SUSE-SU-2020:1301-1
Security update for mailman
openSUSE-SU-2020:1707-1
Recommended update for mailman
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-12137 GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code. | CVSS3: 6.1 | 5% Низкий | почти 6 лет назад | |
CVE-2020-12137 GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code. | CVSS3: 6.1 | 5% Низкий | почти 6 лет назад | |
CVE-2020-12137 GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code. | CVSS3: 6.1 | 5% Низкий | почти 6 лет назад | |
CVE-2020-12137 GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed app ... | CVSS3: 6.1 | 5% Низкий | почти 6 лет назад | |
SUSE-SU-2020:14356-1 Security update for mailman | 5% Низкий | почти 6 лет назад | ||
GHSA-7mvx-jp9h-p8gh GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code. | CVSS3: 6.1 | 5% Низкий | больше 3 лет назад | |
ELSA-2020-4667 ELSA-2020-4667: mailman:2.1 security and bug fix update (MODERATE) | около 5 лет назад | |||
BDU:2020-03997 Уязвимость программного обеспечения для управления рассылками электронных писем Mailman, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных | CVSS3: 4.7 | 5% Низкий | почти 6 лет назад | |
SUSE-SU-2020:1301-1 Security update for mailman | больше 5 лет назад | |||
openSUSE-SU-2020:1707-1 Recommended update for mailman | больше 5 лет назад |
Уязвимостей на страницу