Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
472 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.1% | — | Symantec Brightmail Antispam | 17/12/2004 | 16/6/2026 | The character converters in the Spamhunter and Language ID modules for Symantec Brightmail AntiSpam 6.0.1 before patch 132 allow remote attackers to cause a denial of service (crash) via messages with the ISO-8859-10 character set, which is not recognized by the converters. | |
| Modificada | Media (5) | 1.9% | — | Spamassassin | 20/10/2004 | 16/6/2026 | SpamAssassin 2.5x, and 2.6x before 2.64, allows remote attackers to cause a denial of service via certain malformed messages. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Symantec Brightmail Antispam | 6/8/2004 | 16/6/2026 | Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying the id parameter in a viewMsgDetails.do request. | |
| Modificada | Baja (2.6) | 11% | 💥 Exploit | Symantec Client FirewallSymantec Client SecuritySymantec Norton AntispamSymantec Norton Internet Security+1 | 7/7/2004 | 16/6/2026 | The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop)… | |
| Modificada | Alta (10) | 13% | — | Symantec Client FirewallSymantec Client SecuritySymantec Norton AntispamSymantec Norton Internet Security+1 | 7/7/2004 | 16/6/2026 | Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary… | |
| Modificada | Alta (7.5) | 1.5% | — | Pam-pgsql | 4/5/2004 | 16/6/2026 | SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements. | |
| Modificada | Alta (7.5) | 67% | 💥 Exploit | Symantec Norton Antispam | 15/4/2004 | 16/6/2026 | Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Rhinosoft Zaep Antispam | 14/4/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter. | |
| Modificada | Alta (7.6) | 4.6% | — | Spamassassin | 31/12/2003 | 16/6/2026 | Off-by-one buffer overflow in spamc of SpamAssassin 2.40 through 2.43, when using BSMTP mode ("-B"), allows remote attackers to execute arbitrary code via email containing headers with leading "." characters. | |
| Modificada | Media (4.3) | 1.2% | — | Burton Computer Corporation Spamprobe | 31/12/2003 | 16/6/2026 | SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions. | |
| Modificada | Alta (10) | 2.3% | — | Padl Software PAM Ldap | 20/10/2003 | 16/6/2026 | Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictions and log onto the system. | |
| Modificada | Alta (7.5) | 27% | 💥 Exploit | Dave Airlie PAM SMBRedhat PAM SMB | 20/10/2003 | 16/6/2026 | Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 3.1% | — | Leon J Breedt Pam-pgsql | 27/8/2003 | 16/6/2026 | Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled when recording a log message. | |
| Modificada | Media (4.6) | 0.90% | 💥 Exploit | Andrew Morgan Linux PAM | 24/7/2003 | 16/6/2026 | pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name. | |
| Modificada | Alta (7.5) | 2.4% | — | PAM | 28/10/2002 | 16/6/2026 | PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users. | |
| Modificada | Alta (7.5) | 2.9% | — | C-note Squid Auth LdapPadl Software NSS LdapPadl Software PAM Ldap | 12/8/2002 | 16/6/2026 | Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages. | |
| Modificada | Alta (7.5) | 3.8% | — | Padl Software PAM Ldap | 29/5/2002 | 16/6/2026 | Format string vulnerability in the logging function for the pam_ldap PAM LDAP module before version 144 allows attackers to execute arbitrary code via format strings in the configuration file name. | |
| Modificada | Alta (7.5) | 1.6% | — | Leon J Breedt Pam-pgsql | 10/9/2001 | 16/6/2026 | Leon J Breedt pam-pgsql before 0.5.2 allows remote attackers to execute arbitrary SQL code and bypass authentication or modify user account records by injecting SQL statements into user or password fields. | |
| Modificada | Alta (7.5) | 1.2% | — | PAM Mysql | 19/12/2000 | 23/9/2026 | The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes. | |
| Modificada | Alta (10) | 6.5% | — | Dave Airlie PAM SMBLuke Kenneth Casson Leighton PAM Ntdom | 14/11/2000 | 16/6/2026 | Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name. | |
| Modificada | Media (5) | 7.2% | 💥 Exploit | Michael K. Johnson PAM ConsoleConectiva LinuxRedhat Linux | 27/7/2000 | 16/6/2026 | pam_console PAM module in Linux systems allows a user to access the system console and reboot the system when a display manager such as gdm or kdm has XDMCP enabled. | |
| Modificada | Media (6.2) | 0.33% | — | PAM | 1/12/1998 | 16/6/2026 | Linux PAM modules allow local users to gain root access using temporary files. |