Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Fortinet Fortimail | 4/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add field for the Black List under Antispam Management User… | |
| Modificada | Alta (9.3) | 4.2% | — | Justsystems IchitaroJustsystems Ichitaro Portable With OreplugJustsystems Ichitaro ViewerJustsystems Just Frontier+7 | 27/4/2012 | 16/6/2026 | Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, oreplug, Shuriken Pro4, Shuriken 2007 through 2010, Shuriken Pro4 Corporate Edition,… | |
| Modificada | Media (6.8) | 3.2% | — | Ipswitch Imail | 16/3/2011 | 16/6/2026 | The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command… | |
| Modificada | Alta (9) | 24% | 💥 Exploit | Ipswitch Imail | 27/1/2009 | 16/6/2026 | Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow… | |
| Modificada | Media (4.3) | 1.2% | — | Incredimail | 11/12/2008 | 16/6/2026 | Incredimail build 5853710 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail… | |
| Modificada | Alta (7.5) | 3.2% | — | Ipswitch Imail ClientIpswitch Imail Server | 31/10/2007 | 16/6/2026 | Buffer overflow in IMail Client 9.22, as shipped with IPSwitch IMail Server 2006.22, allows remote attackers to execute arbitrary code via a long boundary parameter in a multipart MIME e-mail message. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Ipswitch Imail | 26/9/2007 | 16/6/2026 | Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary code via a set of four different e-mail messages with a long boundary parameter in a certain malformed Content-Type header line, the string "MIME" by itself on a line in… | |
| Modificada | Alta (7.8) | 2.9% | — | Ipswitch Imail Server | 21/7/2007 | 16/6/2026 | Ipswitch IMail Server 2006 before 2006.21 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving an "overwritten destructor." | |
| Modificada | Media (6.5) | 85% | 💥 Exploit | Ipswitch Imail ServerIpswitch Collaboration Suite | 21/7/2007 | 16/6/2026 | Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command. | |
| Modificada | Alta (10) | 22% | 💥 Exploit | Ipswitch Imail ServerIpswitch Collaboration Suite | 21/7/2007 | 16/6/2026 | Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in Imailsec and (2) allow attackers to have an unknown impact via an unspecified vector related to "subscribe." | |
| Modificada | Media (6.8) | 38% | 💥 Exploit | Incredimail Immenushellext Activex Control | 26/4/2007 | 16/6/2026 | Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 5.6% | — | Ipswitch ImailIpswitch Imail PlusIpswitch Imail PremiumIpswitch Collaboration Suite | 23/3/2007 | 16/6/2026 | Multiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute arbitrary code via the (1) WebConnect and (2) Connect members in the (a) IMailServer control; (3) Sync3 and (4) Init3 members in the (b) IMailLDAPService control; and the… | |
| Modificada | Alta (7.5) | 61% | 💥 Exploit | Ipswitch Imail PlusIpswitch Imail Secure ServerIpswitch Collaboration Suite | 8/9/2006 | 16/6/2026 | Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure allows remote attackers to execute arbitrary code via a long string located after an '@' character and before a ':' character. | |
| Modificada | Baja (2.6) | 2.1% | 💥 Exploit | Sibsoft Communimail | 20/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi and (2) the form_id parameter in templates.cgi. | |
| Modificada | Media (4) | 11% | — | Ipswitch Imail ServerIpswitch Collaboration Suite | 7/12/2005 | 16/6/2026 | The IMAP server in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to cause a denial of service (crash) via a long argument to the LIST command, which causes IMail Server to reference invalid memory. | |
| Modificada | Alta (7.5) | 4.7% | — | Ipswitch Imail ServerIpswitch Collaboration Suite | 7/12/2005 | 16/6/2026 | Format string vulnerability in the SMTP service in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to execute arbitrary code via format string specifiers to the (1) EXPN, (2) MAIL, (3) MAIL FROM, and (4) RCPT TO commands. | |
| Modificada | Alta (7.5) | 2.0% | — | Ipswitch Imail | 6/7/2005 | 16/6/2026 | IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information. | |
| Modificada | Media (5) | 12% | — | Ipswitch ImailIpswitch Imail Server | 25/5/2005 | 16/6/2026 | Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in the query string argument in a GET request to a non-existent .jsp file. | |
| Modificada | Alta (10) | 59% | — | Ipswitch ImailIpswitch Imail ServerIpswitch Collaboration Suite | 25/5/2005 | 16/6/2026 | Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name. | |
| Modificada | Media (5) | 5.1% | — | Ipswitch Imail | 25/5/2005 | 16/6/2026 | Stack-based buffer overflow in the IMAP server for Ipswitch IMail 8.12 and 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to cause a denial of service (crash) via a SELECT command with a large argument. | |
| Modificada | Alta (10) | 43% | 💥 Exploit | Ipswitch ImailIpswitch Imail ServerIpswitch Collaboration Suite | 25/5/2005 | 16/6/2026 | Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins… | |
| Modificada | Media (5) | 8.4% | 💥 Exploit | Ipswitch Imail | 2/5/2005 | 16/6/2026 | Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password. | |
| Modificada | Media (4.6) | 89% | 💥 Exploit | Ipswitch Imail | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command. | |
| Modificada | Media (5) | 4.9% | — | Ipswitch Imail | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the Web calendaring component of Ipswitch IMail Server before 8.13 allows remote attackers to cause a denial of service (crash) via "specific content." | |
| Modificada | Alta (7.5) | 3.5% | — | Ipswitch Imail Express | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text." |