Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
472 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Barracuda Networks Barracuda Spam Firewall | 11/8/2006 | 16/6/2026 | preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file parameter. NOTE: the attack can be extended to arbitrary commands by the presence of CVE-2006-4000. | |
| Modificada | Media (5) | 1.7% | — | Symantec Brightmail Antispam | 7/8/2006 | 16/6/2026 | Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allows remote attackers to cause a denial of service (application freeze) "by sending invalid posts". | |
| Modificada | Alta (7.6) | 4.5% | — | Symantec Brightmail Antispam | 7/8/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and overwrite certain files via directory traversal sequences in (1) DATABLOB-GET and (2) DATABLOB-SAVE requests. | |
| Modificada | Media (4) | 5.8% | 💥 Exploit | Barracuda Networks Barracuda Spam Firewall | 5/8/2006 | 16/6/2026 | Directory traversal vulnerability in cgi-bin/preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Barracuda Networks Barracuda Spam Firewall | 5/8/2006 | 16/6/2026 | Login.pm in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 contains a hard-coded password for the guest account, which allows remote attackers to read sensitive information such as e-mail logs, and possibly e-mail contents and the admin password. | |
| Modificada | Media (6.8) | 34% | 💥 Exploit | Mcafee AntispywareMcafee Internet Security SuiteMcafee Personal Firewall PlusMcafee Privacy Service+5 | 1/8/2006 | 16/6/2026 | Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands… | |
| Modificada | Media (5.1) | 76% | 💥 Exploit | Apache Spamassassin | 6/6/2006 | 16/6/2026 | SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username. | |
| Modificada | Alta (7.5) | 6.3% | — | Pam-mysql | 13/2/2006 | 16/6/2026 | Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer… | |
| Modificada | Media (5) | 2.7% | — | Symantec Brightmail Antispam | 31/12/2005 | 16/6/2026 | Symantec Brightmail AntiSpam 6.0 build 1 and 2 allows remote attackers to cause a denial of service (bmserver component termination) via malformed MIME messages. | |
| Modificada | Media (5) | 1.9% | — | PAM Mysql | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors, probably involving the pam_mysql_sql_log function when being used in vsftpd, which does not include the IP… | |
| Modificada | Media (5) | 7.3% | — | Apache Spamassassin | 20/11/2005 | 16/6/2026 | SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl. | |
| Modificada | Baja (2.1) | 0.43% | — | PAM | 1/11/2005 | 16/6/2026 | The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_chkpwd, which does not log failed guesses or delay its responses. | |
| Modificada | Alta (7.5) | 1.6% | — | Mark D. Roth PAM PER User | 16/9/2005 | 16/6/2026 | pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses the same subrequest handle, which allows remote attackers or local users to login as other users by using certain applications that allow the username to be changed during authentication, such as /bin/login. | |
| Modificada | Alta (7.5) | 53% | 💥 Exploit | Barracuda Networks Barracuda Spam Firewall | 8/9/2005 | 16/6/2026 | img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter. | |
| Modificada | Media (6.4) | 1.4% | — | Barracuda Networks Barracuda Spam Firewall | 8/9/2005 | 16/6/2026 | Argument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source code via the -f option to Dig (dig_device.cgi), (2) determine file existence via the -r argument to Tcpdump (tcpdump_device.cgi) or (3) modify files in the cgi-bin… | |
| Modificada | Media (5) | 8.8% | 💥 Exploit | Barracuda Networks Barracuda Spam Firewall | 8/9/2005 | 16/6/2026 | Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. | |
| Modificada | Alta (7.5) | 3.6% | — | Padl Software PAM Ldap | 23/8/2005 | 16/6/2026 | Unknown vulnerability in pam_ldap before 180 does not properly handle a new password policy control, which could allow attackers to gain privileges. NOTE: CVE-2005-2497 had also been assigned to this issue, but CVE-2005-2641 is the correct candidate. | |
| Modificada | Media (5) | 2.8% | — | Padl NSS LdapPadl PAM Ldap | 30/6/2005 | 16/6/2026 | pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password. | |
| Modificada | Media (5) | 8.3% | — | Apache Spamassassin | 15/6/2005 | 16/6/2026 | Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries. | |
| Modificada | Alta (7.5) | 1.6% | — | Symantec Brightmail Antispam | 9/6/2005 | 16/6/2026 | Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges. | |
| Modificada | Alta (10) | 2.4% | — | Gentoo Poppassd PAM | 2/5/2005 | 16/6/2026 | poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users. | |
| Modificada | Alta (7.5) | 1.3% | — | Barracuda Networks Barracuda Spam Firewall | 2/5/2005 | 16/6/2026 | Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam. | |
| Modificada | Alta (7.5) | 19% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Gateway Security+7 | 8/2/2005 | 16/6/2026 | Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header. | |
| Modificada | Alta (7.5) | 4.6% | — | Enderunix SpamguardAI | 31/12/2004 | 16/6/2026 | Multiple stack-based and heap-based buffer overflows in EnderUNIX spamGuard before 1.7-BETA allow remote attackers to execute arbitrary code via the (1) qmail_parseline and (2) sendmail_parseline functions in parser.c, (3) loadconfig and (4) removespaces functions in loadconfig.c, and possibly (5) unspecified… | |
| Modificada | Alta (7.2) | 0.42% | — | PasswdAILinux-pamAI | 31/12/2004 | 16/6/2026 | passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM. |