Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.2% | — | Gnome EvolutionDebian Linux | 24/1/2005 | 16/6/2026 | Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow. | |
| Modificada | Alta (7.5) | 4.1% | 💥 Exploit | Full Revolution Aspwebcalendar | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Fullrevolution Aspwebalbum | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a… | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Evolutionx | 23/11/2004 | 16/6/2026 | Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server. | |
| Modificada | Media (5) | 3.4% | — | Microsoft Outlook ExpressMozillaMuttQualcomm Eudora+4 | 16/6/2003 | 16/6/2026 | The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors. | |
| Modificada | Alta (7.5) | 2.2% | — | Ximian Evolution | 16/6/2003 | 16/6/2026 | The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors. | |
| Modificada | Media (5) | 0.92% | — | Ximian Evolution | 22/4/2003 | 16/6/2026 | The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack. | |
| Modificada | Media (5) | 10% | 💥 Exploit | Ximian Evolution | 24/3/2003 | 16/6/2026 | The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image. | |
| Modificada | Media (5) | 12% | 💥 Exploit | Ximian Evolution | 24/3/2003 | 16/6/2026 | Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times. | |
| Modificada | Media (5) | 17% | 💥 Exploit | Ximian Evolution | 24/3/2003 | 16/6/2026 | The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow. | |
| Modificada | Media (5) | 1.6% | — | Ximian Evolution | 31/12/2002 | 16/6/2026 | Evolution 1.0.3 and 1.0.4 allows remote attackers to cause a denial of service (memory consumption and crash) via an email with a malformed MIME header. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | PHP Evolution News Evolution | 31/12/2002 | 16/6/2026 | PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php. | |
| Modificada | Alta (7.2) | 0.36% | — | Caldera Volution Manager | 4/10/2002 | 16/6/2026 | Caldera Volution Manager 1.1 stores the Directory Administrator password in cleartext in the slapd.conf file, which could allow local users to gain privileges. | |
| Modificada | Alta (10) | 2.8% | — | Caldera Volution | 8/6/2001 | 16/6/2026 | Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server. |