Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lionel Elie Mamane

#18140of 53,633
15Total CVSS
Vulnerabilities · 2
High
2
PT-2006-3170
7.5
2006-09-19
Gnu · Mailman · CVE-2006-2191
**Name of the Vulnerable Software and Affected Versions** Mailman versions prior to 2.1.9 **Description** A format string issue allows attackers to execute arbitrary code. The vendor has disputed this issue, stating it is unexploitable. **Recommendations** For versions prior to 2.1.9, update to version 2.1.9 or later to resolve the issue.
PT-2006-4022
7.5
2006-09-06
Hylafax · Capi4Hylafax · CVE-2006-3126
**Name of the Vulnerable Software and Affected Versions** capi4hylafax version 01.02.03 **Description** The issue allows remote attackers to execute arbitrary commands via null and shell metacharacters in the TSI string. This can be demonstrated by a fax from an anonymous number, which can include malicious input to exploit the weakness. **Recommendations** For capi4hylafax version 01.02.03, consider restricting or validating input for the TSI string to prevent the inclusion of null and shell metacharacters, which can be used to execute arbitrary commands. As a temporary workaround, restrict access to the c2faxrecv function until a patch is available.