Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

472 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.3%💥 ExploitBarracuda Networks Barracuda Spam Firewall11/8/200616/6/2026
preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file parameter. NOTE: the attack can be extended to arbitrary commands by the presence of CVE-2006-4000.
ModificadaMedia (5)1.7%—Symantec Brightmail Antispam7/8/200616/6/2026
Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allows remote attackers to cause a denial of service (application freeze) "by sending invalid posts".
ModificadaAlta (7.6)4.5%—Symantec Brightmail Antispam7/8/200616/6/2026
Multiple directory traversal vulnerabilities in Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allow remote attackers to read and overwrite certain files via directory traversal sequences in (1) DATABLOB-GET and (2) DATABLOB-SAVE requests.
ModificadaMedia (4)5.8%💥 ExploitBarracuda Networks Barracuda Spam Firewall5/8/200616/6/2026
Directory traversal vulnerability in cgi-bin/preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.
ModificadaAlta (7.5)1.9%—Barracuda Networks Barracuda Spam Firewall5/8/200616/6/2026
Login.pm in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 contains a hard-coded password for the guest account, which allows remote attackers to read sensitive information such as e-mail logs, and possibly e-mail contents and the admin password.
ModificadaMedia (6.8)34%💥 ExploitMcafee AntispywareMcafee Internet Security SuiteMcafee Personal Firewall PlusMcafee Privacy Service+51/8/200616/6/2026
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands…
ModificadaMedia (5.1)76%💥 ExploitApache Spamassassin6/6/200616/6/2026
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.
ModificadaAlta (7.5)6.3%—Pam-mysql13/2/200616/6/2026
Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer…
ModificadaMedia (5)2.7%—Symantec Brightmail Antispam31/12/200516/6/2026
Symantec Brightmail AntiSpam 6.0 build 1 and 2 allows remote attackers to cause a denial of service (bmserver component termination) via malformed MIME messages.
ModificadaMedia (5)1.9%—PAM Mysql31/12/200516/6/2026
Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors, probably involving the pam_mysql_sql_log function when being used in vsftpd, which does not include the IP…
ModificadaMedia (5)7.3%—Apache Spamassassin20/11/200516/6/2026
SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.
ModificadaBaja (2.1)0.43%—PAM1/11/200516/6/2026
The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_chkpwd, which does not log failed guesses or delay its responses.
ModificadaAlta (7.5)1.6%—Mark D. Roth PAM PER User16/9/200516/6/2026
pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses the same subrequest handle, which allows remote attackers or local users to login as other users by using certain applications that allow the username to be changed during authentication, such as /bin/login.
ModificadaAlta (7.5)53%💥 ExploitBarracuda Networks Barracuda Spam Firewall8/9/200516/6/2026
img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.
ModificadaMedia (6.4)1.4%—Barracuda Networks Barracuda Spam Firewall8/9/200516/6/2026
Argument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source code via the -f option to Dig (dig_device.cgi), (2) determine file existence via the -r argument to Tcpdump (tcpdump_device.cgi) or (3) modify files in the cgi-bin…
ModificadaMedia (5)8.8%💥 ExploitBarracuda Networks Barracuda Spam Firewall8/9/200516/6/2026
Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
ModificadaAlta (7.5)3.6%—Padl Software PAM Ldap23/8/200516/6/2026
Unknown vulnerability in pam_ldap before 180 does not properly handle a new password policy control, which could allow attackers to gain privileges. NOTE: CVE-2005-2497 had also been assigned to this issue, but CVE-2005-2641 is the correct candidate.
ModificadaMedia (5)2.8%—Padl NSS LdapPadl PAM Ldap30/6/200516/6/2026
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
ModificadaMedia (5)8.3%—Apache Spamassassin15/6/200516/6/2026
Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.
ModificadaAlta (7.5)1.6%—Symantec Brightmail Antispam9/6/200516/6/2026
Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges.
ModificadaAlta (10)2.4%—Gentoo Poppassd PAM2/5/200516/6/2026
poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users.
ModificadaAlta (7.5)1.3%—Barracuda Networks Barracuda Spam Firewall2/5/200516/6/2026
Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam.
ModificadaAlta (7.5)19%—Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Gateway Security+78/2/200516/6/2026
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
ModificadaAlta (7.5)4.6%—Enderunix SpamguardAI31/12/200416/6/2026
Multiple stack-based and heap-based buffer overflows in EnderUNIX spamGuard before 1.7-BETA allow remote attackers to execute arbitrary code via the (1) qmail_parseline and (2) sendmail_parseline functions in parser.c, (3) loadconfig and (4) removespaces functions in loadconfig.c, and possibly (5) unspecified…
ModificadaAlta (7.2)0.42%—PasswdAILinux-pamAI31/12/200416/6/2026
passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM.
Orbitaley — Vulnerabilidades