Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
472 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Barracuda Networks Barracuda Spam Firewall | 23/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to inject arbitrary web script or HTML via the email parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Guillaume Meister PHP Spammanager | 2/4/2008 | 16/6/2026 | Directory traversal vulnerability in body.php in phpSpamManager (phpSM) 0.53 beta allows remote attackers to read arbitrary local files via a .. (dot dot) in the filename parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Wordpress Math Comment Spam Protection Plugin | 10/1/2008 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to… | |
| Modificada | Media (4.3) | 1.9% | — | Wordpress Math Comment Spam Protection Plugin | 10/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to… | |
| Modificada | Media (4.3) | 1.5% | — | Peters Software Random Anti-spam Image | 10/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 0.2.4 and earlier plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the comment field in the comment form. | |
| Modificada | Alta (9.3) | 3.9% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header. | |
| Modificada | Alta (9.3) | 6.0% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives. | |
| Modificada | Media (4.3) | 1.6% | — | Barracuda Networks Barracuda Spam Firewall | 24/9/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web administration interface in Barracuda Spam Firewall before firmware 3.5.10.016 allows remote attackers to inject arbitrary web script or HTML via the username field in a login attempt, which is not properly handled when the Monitor Web Syslog screen is open. | |
| Modificada | Alta (7.5) | 1.4% | — | Anti-spam Smtp Proxy Server | 10/8/2007 | 16/6/2026 | Unspecified vulnerability in assp.pl in Anti-Spam SMTP Proxy Server (ASSP) 1.3.3 has unknown impact and attack vectors. | |
| Modificada | Media (4.4) | 0.28% | — | Kaspersky LAB Kaspersky Anti-spam | 8/8/2007 | 16/6/2026 | Kaspersky Anti-Spam 3.0 MP1 before Critical Fix 2 (3.0.278.4) sets incorrect permissions for application files in certain upgrade scenarios, which might allow local users to gain privileges. | |
| Modificada | Media (6.9) | 1.1% | 💥 Exploit | Symantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+2 | 15/7/2007 | 16/6/2026 | Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt… | |
| Modificada | Alta (7.5) | 1.7% | — | Kaspersky LAB Kaspersky Anti-spam | 30/6/2007 | 16/6/2026 | Unspecified vulnerability in the web-based product configuration system in Kaspersky Anti-Spam before 3.0 MP1 allows remote attackers to obtain access to certain directories. | |
| Modificada | Baja (1.9) | 0.34% | — | Spamassassin | 11/6/2007 | 16/6/2026 | SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd. | |
| Modificada | Alta (7.8) | 3.2% | — | AmavisAvast AntivirusAvast Antivirus HomeAvast Antivirus Professional+9 | 9/5/2007 | 16/6/2026 | unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. | |
| Modificada | Media (4.9) | 1.7% | 💥 Exploit | Symantec AntivirusSymantec Client SecuritySymantec Norton 360Symantec Norton Antispam+4 | 2/4/2007 | 16/6/2026 | SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2)… | |
| Modificada | Baja (1.9) | 0.86% | 💥 Exploit | Symantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+2 | 16/3/2007 | 16/6/2026 | The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's… | |
| Modificada | Media (4.3) | 6.9% | — | Apache Spamassassin | 16/2/2007 | 16/6/2026 | Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage." | |
| Modificada | Media (6.4) | 0.88% | — | PAM SSH | 8/2/2007 | 16/6/2026 | The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase. | |
| Modificada | Alta (7.2) | 0.40% | — | Andrew Morgan Linux PAM | 23/1/2007 | 16/6/2026 | pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters. | |
| Modificada | Baja (2.1) | 0.31% | — | PAM Extern | 3/11/2006 | 16/6/2026 | PAM_extern before 0.2 sends a password as a command line argument, which allows local users to obtain the password by listing the command line arguments, such as ps. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Spamoborona | 18/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Media (6.8) | 5.5% | 💥 Exploit | Phpbb Spamblockermod | 17/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Media (4) | 1.1% | — | John Hanna Anti-spam Smtp Proxy Server | 21/8/2006 | 16/6/2026 | Absolute path traversal vulnerability in the get functionality in Anti-Spam SMTP Proxy (ASSP) allows remote authenticated users to read arbitrary files via (1) C:\ (Windows drive letter), (2) UNC, and possibly other types of paths in the file parameter. | |
| Modificada | Media (5.1) | 3.1% | 💥 Exploit | Spaminator | 16/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Alta (7.2) | 0.36% | — | Barracuda Networks Barracuda Spam Firewall | 11/8/2006 | 16/6/2026 | Barracuda Spam Firewall (BSF), possibly 3.3.03.053, contains a hardcoded password for the admin account for logins from 127.0.0.1 (localhost), which allows local users to gain privileges. |