Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 4.1% | 💥 Exploit | Icewarp Email ServerIcewarp Webmail Server | 5/5/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2)… | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Icewarp Merak Mail Server | 4/5/2009 | 16/6/2026 | Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent attackers to execute arbitrary code via a large value in the second argument to the Base64FileEncode method, as possibly demonstrated by a web application that accepts… | |
| Modificada | Alta (7.6) | 2.8% | — | Mcafee Active Virus DefenseMcafee Active VirusscanMcafee Email GatewayMcafee Internet Security Suite+9 | 30/4/2009 | 16/6/2026 | The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in… | |
| Modificada | Media (4.3) | 1.3% | — | Gecad Axigen Mail Server | 29/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web mail interface feature in AXIGEN Mail Server 6.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving e-mail messages. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Noticeware Email Server NG | 19/2/2009 | 16/6/2026 | NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 requests with a long PASS command. | |
| Modificada | Media (4.3) | 1.1% | — | Icewarp Merak Mail Server | 26/12/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp Software Merak Mail Server 9.3.2 allows remote attackers to inject arbitrary web script or HTML via an IMG element in an HTML e-mail message. | |
| Modificada | Alta (9) | 5.5% | 💥 Exploit | Comingchina U-mail Webmail Server | 5/11/2008 | 16/6/2026 | webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root. | |
| Modificada | Media (4) | 2.3% | 💥 Exploit | Softalk Mail Server | 11/9/2008 | 16/6/2026 | The IMAP server in Softalk Mail Server (formerly WorkgroupMail) 8.5.1.431 allows remote authenticated users to cause a denial of service (resource consumption and daemon crash) via a long IMAP APPEND command with certain repeated parameters. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Noticeware Email Server | 12/8/2008 | 16/6/2026 | The IMAP server in NoticeWare Email Server NG 4.6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via multiple long LOGIN commands. | |
| Modificada | Media (4.3) | 1.3% | — | E-post Corporation Mail Server | 1/5/2008 | 16/6/2026 | The POP3 server (EPSTPOP3S.EXE) 4.22 in E-Post Mail Server 4.10 allows remote attackers to obtain sensitive information via multiple crafted APOP commands for a known POP3 account, which displays the password in a POP3 error message. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Noticeware Email Server | 9/4/2008 | 16/6/2026 | MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application crash) via a long string to IMAP port (143/tcp). | |
| Modificada | Alta (7.5) | 4.0% | — | Kerio MailserverVisnetic Antivirus Plug-in FOR Mail Server | 21/2/2008 | 16/6/2026 | Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Gecad Technologies Axigen Mail Server | 23/1/2008 | 16/6/2026 | Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command. | |
| Modificada | Media (4.3) | 3.0% | 💥 Exploit | Merak Icewarp Mail Server | 10/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HTML via the message parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4) | 1.4% | — | Code-crafters Ability Mail Server | 23/11/2007 | 16/6/2026 | Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, and possibly (2) a blank string in unspecified messages. | |
| Modificada | Alta (7.5) | 3.2% | — | Ipswitch Imail ClientIpswitch Imail Server | 31/10/2007 | 16/6/2026 | Buffer overflow in IMail Client 9.22, as shipped with IPSwitch IMail Server 2006.22, allows remote attackers to execute arbitrary code via a long boundary parameter in a multipart MIME e-mail message. | |
| Modificada | Media (4.3) | 1.1% | — | Icewarp Merak Mail Server | 24/9/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Webmail interface for IceWarp Merak Mail Server before 9.0.0 allows remote attackers to inject arbitrary JavaScript via a javascript: URI in an attribute of an element in an email message body, as demonstrated by the onload attribute in a BODY element. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Hexamail Server | 31/8/2007 | 16/6/2026 | Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long USER command. | |
| Modificada | Alta (10) | 22% | 💥 Exploit | Ipswitch Imail ServerIpswitch Collaboration Suite | 21/7/2007 | 16/6/2026 | Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in Imailsec and (2) allow attackers to have an unknown impact via an unspecified vector related to "subscribe." | |
| Modificada | Alta (7.8) | 2.9% | — | Ipswitch Imail Server | 21/7/2007 | 16/6/2026 | Ipswitch IMail Server 2006 before 2006.21 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving an "overwritten destructor." | |
| Modificada | Media (6.5) | 85% | 💥 Exploit | Ipswitch Imail ServerIpswitch Collaboration Suite | 21/7/2007 | 16/6/2026 | Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command. | |
| Modificada | Alta (10) | 8.7% | 💥 Exploit | Gecad Technologies Axigen Mail Server | 12/2/2007 | 16/6/2026 | Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via certain base64-encoded data on the pop3 port (110/tcp), which triggers an integer overflow. | |
| Modificada | Alta (7.8) | 10% | 💥 Exploit | Gecad Technologies Axigen Mail Server | 12/2/2007 | 16/6/2026 | axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded "*\x00" sequence on the imap port (143/tcp). | |
| Modificada | Media (4) | 2.1% | — | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 21/7/2006 | 16/6/2026 | Absolute path directory traversal vulnerability in (1) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (2) VisNetic MailServer before 8.5.0.5 allows remote authenticated users to include arbitrary files via a modified language parameter and a full Windows or UNC pathname in the… | |
| Modificada | Media (5) | 5.7% | — | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 21/7/2006 | 16/6/2026 | Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php… |