Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.43%—Trend Micro Scanmail Exchange22/8/200116/6/2026
TrendMicro ScanMail for Exchange 3.5 Evaluation allows a local attacker to recover the administrative credentials for ScanMail via a combination of unprotected registry keys and weakly encrypted passwords.
ModificadaAlta (7.5)6.4%—Microsoft Exchange Server21/7/200116/6/2026
An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
ModificadaMedia (5)33%—Microsoft Exchange Server16/7/200116/6/2026
Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaMedia (5)37%—Microsoft Exchange ServerMicrosoft Internet Information Services2/6/200116/6/2026
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
ModificadaMedia (5)20%—Microsoft Exchange Server12/3/200116/6/2026
Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.
ModificadaAlta (7.5)5.0%—Microsoft Exchange Server9/1/200116/6/2026
The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.
ModificadaAlta (7.5)2.4%💥 ExploitBroadcom Inoculateit Agent FOR Exchange31/12/200023/9/2026
Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field, which allows remote attackers to bypass virus protection.
ModificadaMedia (5)15%—Microsoft Exchange Server11/12/200016/6/2026
Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability.
ModificadaMedia (5)15%—Microsoft Exchange ServerMicrosoft Outlook5/6/200016/6/2026
Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.
ModificadaMedia (5)5.1%—Microsoft Exchange ServerMicrosoft OutlookMicrosoft Windows Messaging29/2/200016/6/2026
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.
ModificadaMedia (5)13%—Microsoft Exchange Server31/12/199916/6/2026
Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).
ModificadaAlta (7.5)7.1%—Microsoft Exchange Server13/12/199916/6/2026
Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.
ModificadaMedia (5)26%—Microsoft Exchange Server6/8/199916/6/2026
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
ModificadaAlta (10)18%—Microsoft Exchange Server1/12/199816/6/2026
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
ModificadaMedia (4.6)1.5%—Broadcom Arcserve BackupBroadcom InoculanMicrosoft Exchange Server12/11/199816/6/2026
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.
ModificadaMedia (5)7.6%—C2net Stonghold WEB ServerHP Open Market Secure WebserverMicrosoft Exchange ServerMicrosoft Internet Information Server+926/6/199816/6/2026
Information from SSL-encrypted sessions via PKCS #1.
ModificadaAlta (7.5)12%💥 ExploitIBM Lotus Domino Mail ServerMicrosoft Exchange Server1/1/199816/6/2026
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
Orbitaley — Vulnerabilidades