Lyris Technologies develops ListManager, an email-list management and marketing-automation platform that serves a defined niche in messaging infrastructure. The product's vulnerability profile reflects its role handling user input and list data, with public exploit code available for disclosed vulnerabilities. Severity and exploitation trends are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lyris Technologies Inc over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4145MEDIUM The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space ("lyris" and up to 5 digits, possibly f | Dec 10, 2005 | 6.5 | 58 | NO | YES |
CVE-2005-4142HIGH The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list admini | Dec 10, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-4147MEDIUM The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00) | Dec 10, 2005 | 6.5 | 18 | NO | NO |
CVE-2005-4146MEDIUM Lyris ListManager before 8.9b allows remote attackers to obtain sensitive information via a request to the TCLHTTPd status module, which provides sensitive server configuration inf | Dec 10, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-4148MEDIUM Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such a | Dec 10, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-4149MEDIUM Lyris ListManager 8.8 through 8.9b allows remote attackers to obtain sensitive information by causing errors in TML scripts, such as via direct requests, which leaks the installati | Dec 10, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lyris Technologies Inc.
Media articles that mention a CVE ID that affects a product developed by Lyris Technologies Inc — matched by CVE ID, not by vendor name.