Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

102 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)6.4%—University OF Washington AlpineUniversity OF Washington Imap Toolkit10/11/200816/6/2026
Multiple stack-based buffer overflows in (1) University of Washington IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine 2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain privileges by specifying a long folder extension argument on the command line to the tmail or dmail program; and…
ModificadaMedia (6.8)2.1%—Stephane Pineau Vote17/8/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in depouilg.php3 in Stephane Pineau VOTE 1c allow remote attackers to execute arbitrary PHP code via a URL in the (1) NomVote and (2) FilePalHex parameters.
ModificadaAlta (7.5)1.2%—Pineapple Technologies Lore12/4/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to…
ModificadaMedia (4.3)3.6%—Pineapple Technologies Quizshock10/4/200716/6/2026
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<".
ModificadaMedia (6.8)1.3%—Spine8/1/200716/6/2026
Cross-site request forgery (CSRF) vulnerability in SPINE allows remote attackers to perform unauthorized actions as administrators via unspecified vectors. NOTE: some of these details are obtained from third party information.
ModificadaAlta (10)1.4%—Spine31/12/200616/6/2026
Multiple unspecified vulnerabilities in SPINE before 1.2 have unknown impact and attack vectors, related to (1) "Placeholders in database handler" and (2) "Macro admin security."
ModificadaAlta (7.5)1.2%—Pineapple Technologies Lore6/6/200616/6/2026
SQL injection vulnerability in comment.php in Pineapple Technologies Lore 1.5.6 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
ModificadaMedia (6.6)0.39%—Gentoo App-crypt PinentryGentoo Linux4/1/200616/6/2026
The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.
ModificadaAlta (7.5)1.2%—Pineapple Technologies Lore4/12/200516/6/2026
SQL injection vulnerability in article.php in Pineapple Technologies Lore 1.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaBaja (1.2)0.30%—University OF Washington Pine2/5/200516/6/2026
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.
ModificadaAlta (7.5)13%—University OF Washington Pine17/9/200316/6/2026
Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.
ModificadaAlta (7.5)4.0%—Washington Pine17/9/200316/6/2026
Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.
ModificadaMedia (5)3.4%—Microsoft Outlook ExpressMozillaMuttQualcomm Eudora+416/6/200316/6/2026
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
ModificadaAlta (7.5)2.7%—University OF Washington C-clientUniversity OF Washington Imap-2002bUniversity OF Washington Pine16/6/200316/6/2026
c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.
ModificadaMedia (5)1.4%—University OF Washington Pine31/12/200216/6/2026
Pine 4.2.1 through 4.4.4 puts Unix usernames and/or uid into Sender: and X-Sender: headers, which could allow remote attackers to obtain sensitive information.
ModificadaAlta (7.8)3.5%—University OF Washington Pine31/12/200216/6/2026
The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field.
ModificadaMedia (5)9.6%—University OF Washington Pine11/12/200216/6/2026
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").
ModificadaAlta (7.5)2.2%—University OF Washington Pine26/7/200216/6/2026
URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).
ModificadaBaja (2.1)0.81%—ImmunixUniversity OF Washington PineEngardelinux Secure LinuxMandrakesoft Mandrake Linux+218/10/200116/6/2026
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.
ModificadaBaja (2.6)1.5%—Holger Lamm Pgp4pine3/5/200116/6/2026
pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext.
ModificadaAlta (7.5)12%—University OF Washington Pine19/12/200023/9/2026
Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.
ModificadaAlta (7.5)2.5%—University OF Washington ImapUniversity OF Washington Pine14/11/200016/6/2026
Buffer overflow in University of Washington c-client library (used by pine and other programs) allows remote attackers to execute arbitrary commands via a long X-Keywords header.
ModificadaAlta (10)3.5%—University OF Washington Pine18/11/199916/6/2026
Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.
ModificadaAlta (10)3.8%—University OF Washington Pine28/6/199916/6/2026
Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.
ModificadaMedia (5)1.6%—Seapine Software Testtrack8/3/199916/6/2026
Seapine Software TestTrack server allows a remote attacker to cause a denial of service (high CPU) via (1) TestTrackWeb.exe and (2) ttcgi.exe by connecting to port 99 and disconnecting without sending any data.