Great Circle Associates maintains legacy mailing-list and messaging software, particularly Majordomo and related products, that despite limited current deployment remains relevant in older infrastructure and niche communities. The vendor's vulnerability profile shows a tendency toward public exploit availability, reflecting the age and accessibility of the codebase to security researchers. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Great Circle Associates over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-0207HIGH Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command. | Jun 9, 1994 | 7.5 | 32 | NO | YES |
CVE-2003-1367HIGH The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresse | Dec 31, 2003 | 7.8 | 25 | NO | NO |
CVE-2000-0035MEDIUM resend command in Majordomo allows local users to gain privileges via shell metacharacters. | Dec 28, 1999 | 4.6 | 21 | NO | YES |
CVE-2000-0037MEDIUM Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file. | Dec 28, 1999 | 4.6 | 21 | NO | YES |
CVE-1999-1220HIGH Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharac | Aug 24, 1997 | 7.5 | 20 | NO | NO |
MajorCool mj_key_cache program allows local users to modify files via a symlink attack. | Jun 18, 1997 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Great Circle Associates.
Media articles that mention a CVE ID that affects a product developed by Great Circle Associates — matched by CVE ID, not by vendor name.