Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

53 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.7%—Debian Mime-support6/1/201517/6/2026
run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.
ModificadaMedia (4)1.2%—Mime Mail Module Project Mimemail31/10/201216/6/2026
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.
ModificadaMedia (5)2.2%—F-secure Anti-virusF-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR Citrix Servers+1015/4/201016/6/2026
F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02 and earlier; Anti-Virus 2010 and earlier; Home Server Security 2009; Protection Service for Consumers 9 and earlier,…
ModificadaAlta (7.5)3.3%—Gnome Gmime8/2/201016/6/2026
Buffer overflow in the GMIME_UUENCODE_LEN macro in gmime/gmime-encodings.h in GMime before 2.4.15 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via input data for a uuencode operation.
ModificadaAlta (10)2.3%—Forkosh Mimetex14/7/200916/6/2026
Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \environ, (2) \input, and (3) \counter TeX directives.
ModificadaAlta (10)9.0%—Forkosh Mimetex14/7/200916/6/2026
Multiple stack-based buffer overflows in mimetex.cgi in mimeTeX, when downloaded before 20090713, allow remote attackers to execute arbitrary code via a TeX file with long (1) picture, (2) circle, or (3) input tags.
ModificadaAlta (7.6)5.5%—F-secure Anti-virusF-secure Anti-virus FOR Citrix ServersF-secure Anti-virus FOR Microsoft ExchangeF-secure Anti-virus FOR Mimesweeper+136/2/200916/6/2026
Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer…
ModificadaAlta (7.5)3.5%—Roaring Penguin Mimedefang12/2/200716/6/2026
Buffer overflow in Roaring Penguin MIMEDefang 2.59 and 2.60 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors.
ModificadaMedia (5)1.6%—Clearswift Mimesweeper FOR WEB12/7/200616/6/2026
Clearswift MIMEsweeper for Web before 5.1.15 Hotfix allows remote attackers to cause a denial of service (crash) via an encrypted archived .RAR file, which triggers a scan error and causes the Web Policy Engine service to terminate.
ModificadaMedia (4.3)1.8%—Clearswift Mimesweeper FOR WEB12/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in Clearswift MIMEsweeper for Web before 5.1.15 Hotfix allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in an error message when trying to access a blocked web site.
ModificadaMedia (5)1.7%—Clearswift Mimesweeper FOR WEB28/12/200516/6/2026
Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0 through 5.1 allows remote attackers to bypass filtering via a URL that does not include a .exe extension but returns an executable file.
ModificadaAlta (7.5)4.2%—Squirrelmail S Mime Plugin2/5/200516/6/2026
viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.
ModificadaAlta (7.5)1.6%—Roaring Penguin MimedefangMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerSuse Linux10/1/200516/6/2026
MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Content-Type header.
ModificadaMedia (4.3)1.1%—Clearswift Mailsweeper Business Suite IClearswift Mailsweeper Business Suite IIClearswift Mailsweeper FOR SmtpClearswift Mimesweeper FOR WEB31/12/200416/6/2026
Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".
ModificadaAlta (7.5)1.5%—Paul L Daniels Ripmime31/12/200416/6/2026
ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted.
ModificadaMedia (5)0.87%—Paul L Daniels Ripmime31/12/200416/6/2026
The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers, which leads to a buffer underflow.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use fields that use RFC2047 encoding, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplicate quotes, or (3) missing leading or trailing quote characters,…
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.
ModificadaMedia (5)2.0%—Clearswift Mimesweeper FOR WEB11/8/200416/6/2026
Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via "..\\", "..\", and similar dot dot sequences in the URL.
ModificadaMedia (4.6)0.32%—Debian Mime-support12/5/200316/6/2026
run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.