Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

103 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.4%💥 ExploitFortinet Fortimail4/2/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add field for the Black List under Antispam Management User…
ModificadaAlta (9.3)4.2%—Justsystems IchitaroJustsystems Ichitaro Portable With OreplugJustsystems Ichitaro ViewerJustsystems Just Frontier+727/4/201216/6/2026
Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, oreplug, Shuriken Pro4, Shuriken 2007 through 2010, Shuriken Pro4 Corporate Edition,…
ModificadaMedia (6.8)3.2%—Ipswitch Imail16/3/201116/6/2026
The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command…
ModificadaAlta (9)24%💥 ExploitIpswitch Imail27/1/200916/6/2026
Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow…
ModificadaMedia (4.3)1.2%—Incredimail11/12/200816/6/2026
Incredimail build 5853710 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail…
ModificadaAlta (7.5)3.2%—Ipswitch Imail ClientIpswitch Imail Server31/10/200716/6/2026
Buffer overflow in IMail Client 9.22, as shipped with IPSwitch IMail Server 2006.22, allows remote attackers to execute arbitrary code via a long boundary parameter in a multipart MIME e-mail message.
ModificadaAlta (7.5)4.4%💥 ExploitIpswitch Imail26/9/200716/6/2026
Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary code via a set of four different e-mail messages with a long boundary parameter in a certain malformed Content-Type header line, the string "MIME" by itself on a line in…
ModificadaAlta (7.8)2.9%—Ipswitch Imail Server21/7/200716/6/2026
Ipswitch IMail Server 2006 before 2006.21 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving an "overwritten destructor."
ModificadaMedia (6.5)85%💥 ExploitIpswitch Imail ServerIpswitch Collaboration Suite21/7/200716/6/2026
Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.
ModificadaAlta (10)22%💥 ExploitIpswitch Imail ServerIpswitch Collaboration Suite21/7/200716/6/2026
Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in Imailsec and (2) allow attackers to have an unknown impact via an unspecified vector related to "subscribe."
ModificadaMedia (6.8)38%💥 ExploitIncredimail Immenushellext Activex Control26/4/200716/6/2026
Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (9.3)5.6%—Ipswitch ImailIpswitch Imail PlusIpswitch Imail PremiumIpswitch Collaboration Suite23/3/200716/6/2026
Multiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute arbitrary code via the (1) WebConnect and (2) Connect members in the (a) IMailServer control; (3) Sync3 and (4) Init3 members in the (b) IMailLDAPService control; and the…
ModificadaAlta (7.5)61%💥 ExploitIpswitch Imail PlusIpswitch Imail Secure ServerIpswitch Collaboration Suite8/9/200616/6/2026
Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure allows remote attackers to execute arbitrary code via a long string located after an '@' character and before a ':' character.
ModificadaBaja (2.6)2.1%💥 ExploitSibsoft Communimail20/4/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi and (2) the form_id parameter in templates.cgi.
ModificadaMedia (4)11%—Ipswitch Imail ServerIpswitch Collaboration Suite7/12/200516/6/2026
The IMAP server in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to cause a denial of service (crash) via a long argument to the LIST command, which causes IMail Server to reference invalid memory.
ModificadaAlta (7.5)4.7%—Ipswitch Imail ServerIpswitch Collaboration Suite7/12/200516/6/2026
Format string vulnerability in the SMTP service in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to execute arbitrary code via format string specifiers to the (1) EXPN, (2) MAIL, (3) MAIL FROM, and (4) RCPT TO commands.
ModificadaAlta (7.5)2.0%—Ipswitch Imail6/7/200516/6/2026
IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.
ModificadaMedia (5)12%—Ipswitch ImailIpswitch Imail Server25/5/200516/6/2026
Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in the query string argument in a GET request to a non-existent .jsp file.
ModificadaAlta (10)59%—Ipswitch ImailIpswitch Imail ServerIpswitch Collaboration Suite25/5/200516/6/2026
Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name.
ModificadaMedia (5)5.1%—Ipswitch Imail25/5/200516/6/2026
Stack-based buffer overflow in the IMAP server for Ipswitch IMail 8.12 and 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to cause a denial of service (crash) via a SELECT command with a large argument.
ModificadaAlta (10)43%💥 ExploitIpswitch ImailIpswitch Imail ServerIpswitch Collaboration Suite25/5/200516/6/2026
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins…
ModificadaMedia (5)8.4%💥 ExploitIpswitch Imail2/5/200516/6/2026
Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.
ModificadaMedia (4.6)89%💥 ExploitIpswitch Imail31/12/200416/6/2026
Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.
ModificadaMedia (5)4.9%—Ipswitch Imail31/12/200416/6/2026
Unknown vulnerability in the Web calendaring component of Ipswitch IMail Server before 8.13 allows remote attackers to cause a denial of service (crash) via "specific content."
ModificadaAlta (7.5)3.5%—Ipswitch Imail Express31/12/200416/6/2026
Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text."
Orbitaley — Vulnerabilidades