Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 6.4% | — | University OF Washington AlpineUniversity OF Washington Imap Toolkit | 10/11/2008 | 16/6/2026 | Multiple stack-based buffer overflows in (1) University of Washington IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine 2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain privileges by specifying a long folder extension argument on the command line to the tmail or dmail program; and… | |
| Modificada | Media (6.8) | 2.1% | — | Stephane Pineau Vote | 17/8/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in depouilg.php3 in Stephane Pineau VOTE 1c allow remote attackers to execute arbitrary PHP code via a URL in the (1) NomVote and (2) FilePalHex parameters. | |
| Modificada | Alta (7.5) | 1.2% | — | Pineapple Technologies Lore | 12/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to… | |
| Modificada | Media (4.3) | 3.6% | — | Pineapple Technologies Quizshock | 10/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<". | |
| Modificada | Media (6.8) | 1.3% | — | Spine | 8/1/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in SPINE allows remote attackers to perform unauthorized actions as administrators via unspecified vectors. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 1.4% | — | Spine | 31/12/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in SPINE before 1.2 have unknown impact and attack vectors, related to (1) "Placeholders in database handler" and (2) "Macro admin security." | |
| Modificada | Alta (7.5) | 1.2% | — | Pineapple Technologies Lore | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in comment.php in Pineapple Technologies Lore 1.5.6 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter. | |
| Modificada | Media (6.6) | 0.39% | — | Gentoo App-crypt PinentryGentoo Linux | 4/1/2006 | 16/6/2026 | The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0. | |
| Modificada | Alta (7.5) | 1.2% | — | Pineapple Technologies Lore | 4/12/2005 | 16/6/2026 | SQL injection vulnerability in article.php in Pineapple Technologies Lore 1.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Baja (1.2) | 0.30% | — | University OF Washington Pine | 2/5/2005 | 16/6/2026 | Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Alta (7.5) | 13% | — | University OF Washington Pine | 17/9/2003 | 16/6/2026 | Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type. | |
| Modificada | Alta (7.5) | 4.0% | — | Washington Pine | 17/9/2003 | 16/6/2026 | Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number. | |
| Modificada | Media (5) | 3.4% | — | Microsoft Outlook ExpressMozillaMuttQualcomm Eudora+4 | 16/6/2003 | 16/6/2026 | The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors. | |
| Modificada | Alta (7.5) | 2.7% | — | University OF Washington C-clientUniversity OF Washington Imap-2002bUniversity OF Washington Pine | 16/6/2003 | 16/6/2026 | c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors. | |
| Modificada | Media (5) | 1.4% | — | University OF Washington Pine | 31/12/2002 | 16/6/2026 | Pine 4.2.1 through 4.4.4 puts Unix usernames and/or uid into Sender: and X-Sender: headers, which could allow remote attackers to obtain sensitive information. | |
| Modificada | Alta (7.8) | 3.5% | — | University OF Washington Pine | 31/12/2002 | 16/6/2026 | The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field. | |
| Modificada | Media (5) | 9.6% | — | University OF Washington Pine | 11/12/2002 | 16/6/2026 | Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks ("). | |
| Modificada | Alta (7.5) | 2.2% | — | University OF Washington Pine | 26/7/2002 | 16/6/2026 | URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&). | |
| Modificada | Baja (2.1) | 0.81% | — | ImmunixUniversity OF Washington PineEngardelinux Secure LinuxMandrakesoft Mandrake Linux+2 | 18/10/2001 | 16/6/2026 | Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Baja (2.6) | 1.5% | — | Holger Lamm Pgp4pine | 3/5/2001 | 16/6/2026 | pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext. | |
| Modificada | Alta (7.5) | 12% | — | University OF Washington Pine | 19/12/2000 | 23/9/2026 | Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header. | |
| Modificada | Alta (7.5) | 2.5% | — | University OF Washington ImapUniversity OF Washington Pine | 14/11/2000 | 16/6/2026 | Buffer overflow in University of Washington c-client library (used by pine and other programs) allows remote attackers to execute arbitrary commands via a long X-Keywords header. | |
| Modificada | Alta (10) | 3.5% | — | University OF Washington Pine | 18/11/1999 | 16/6/2026 | Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL. | |
| Modificada | Alta (10) | 3.8% | — | University OF Washington Pine | 28/6/1999 | 16/6/2026 | Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine. | |
| Modificada | Media (5) | 1.6% | — | Seapine Software Testtrack | 8/3/1999 | 16/6/2026 | Seapine Software TestTrack server allows a remote attacker to cause a denial of service (high CPU) via (1) TestTrackWeb.exe and (2) ttcgi.exe by connecting to port 99 and disconnecting without sending any data. |