Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.8% | — | Hitachi Groupmax Address ServerHitachi Groupmax Mail Server | 24/6/2006 | 16/6/2026 | Unspecified vulnerability in Hitachi Groupmax Address Server 7 and earlier, and Groupmax Mail Server 7 and earlier allows remote attackers to cause a denial of service (product "stop") via unspecified vectors involving "unexpected requests". | |
| Modificada | Media (4.3) | 1.4% | — | Emailarchitect Email Server | 21/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EmailArchitect Email Server 6.1 allows remote attackers to inject arbitrary Javascript via an HTML div tag with a carriage return between the onmouseover attribute and its value, which bypasses the mail filter. | |
| Modificada | Baja (2.6) | 1.9% | — | Emailarchitect Email Server | 12/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 6.1.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errCode and (2) uid parameter in (a) default.asp and (3) dname parameter in (b) /admin/dns.asp and (c) /additional/regdomain_done.asp. | |
| Modificada | Media (4.3) | 2.2% | — | Argosoft Mail Server | 3/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the View Headers (aka viewheaders) functionality in ArGoSoft Mail Server Pro 1.8.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the Subject header, (2) the From header, and (3) certain other unspecified headers. | |
| Modificada | Media (4) | 1.4% | — | Argosoft Mail Server | 28/2/2006 | 16/6/2026 | Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the UIDL parameter. | |
| Modificada | Media (5) | 2.1% | — | Argosoft Mail Server | 28/2/2006 | 16/6/2026 | The POP3 Server in ArGoSoft Mail Server Pro 1.8 allows remote attackers to obtain sensitive information via the _DUMP command, which reveals the operating system, registered user, and registration code. | |
| Modificada | Media (4) | 1.3% | — | Argosoft Mail Server | 28/2/2006 | 16/6/2026 | Directory traversal vulnerability in the IMAP server in ArGoSoft Mail Server Pro 1.8.8.1 allows remote authenticated users to create arbitrary folders via a .. (dot dot) in the RENAME command. | |
| Modificada | Alta (7.2) | 0.37% | — | Visnetic Antivirus Plug-in FOR Mail Server | 23/2/2006 | 16/6/2026 | The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6.1.2, does not drop privileges before executing other programs, which allows local users to gain privileges. | |
| Modificada | Alta (7.5) | 2.1% | — | E-post Corporation Mail ServerE-post Corporation Spa-pro Mail Atsolomon | 27/1/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in (1) EPSTIMAP4S.EXE and (2) SPA-IMAP4S.EXE in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allow remote attackers to (a) list arbitrary directories or cause a denial of service via the LIST command; or create arbitrary files via the (b) APPEND, (c) COPY, or… | |
| Modificada | Media (5) | 1.8% | — | E-post Corporation Mail ServerE-post Corporation Spa-pro Mail Atsolomon | 27/1/2006 | 16/6/2026 | Early termination vulnerability in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allows remote attackers to cause a denial of service (infinite loop) by sending an APPEND command and disconnecting before the expected amount of data is sent. | |
| Modificada | Alta (7.5) | 4.6% | — | E-post Corporation Mail ServerE-post Corporation Smtp ServerE-post Corporation Spa-pro Mail Atsolomon | 27/1/2006 | 16/6/2026 | Multiple buffer overflows in E-Post Mail Server 4.10 and SPA-PRO Mail @Solomon 4.00 allow remote attackers to execute arbitrary code via a long username to the (1) AUTH PLAIN or (2) AUTH LOGIN SMTP commands, which is not properly handled by (a) EPSTRS.EXE or (b) SPA-RS.EXE; (3) a long username in the APOP POP3… | |
| Modificada | Media (5) | 2.8% | — | Eudora Internet Mail Server | 9/1/2006 | 16/6/2026 | Qualcomm Eudora Internet Mail Server (EIMS) before 3.2.8 allows remote attackers to cause a denial of service (crash) via (1) malformed NTLM authentication requests, or a malformed (2) Incoming Mail X or (3) Temporary Mail file. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 28/12/2005 | 16/6/2026 | PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters… | |
| Modificada | Media (5) | 8.6% | 💥 Exploit | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 28/12/2005 | 16/6/2026 | mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings variables when an unrecognized HTTP_USER_AGENT string is provided, which allows remote attackers to access arbitrary files… | |
| Modificada | Media (5) | 9.5% | 💥 Exploit | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 28/12/2005 | 16/6/2026 | dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local files via a null byte (%00) in the lang parameter, possibly due to a directory traversal vulnerability. | |
| Modificada | Media (6.5) | 8.5% | 💥 Exploit | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 28/12/2005 | 16/6/2026 | IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL… | |
| Modificada | Alta (7.5) | 1.6% | — | Double Precision Incorporated Courier Mail Server | 11/12/2005 | 16/6/2026 | authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled. | |
| Modificada | Media (4) | 11% | — | Ipswitch Imail ServerIpswitch Collaboration Suite | 7/12/2005 | 16/6/2026 | The IMAP server in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to cause a denial of service (crash) via a long argument to the LIST command, which causes IMail Server to reference invalid memory. | |
| Modificada | Alta (7.5) | 4.7% | — | Ipswitch Imail ServerIpswitch Collaboration Suite | 7/12/2005 | 16/6/2026 | Format string vulnerability in the SMTP service in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to execute arbitrary code via format string specifiers to the (1) EXPN, (2) MAIL, (3) MAIL FROM, and (4) RCPT TO commands. | |
| Modificada | Media (5) | 7.3% | 💥 Exploit | Amax Information Technologies Magic Winmail Server | 25/11/2005 | 16/6/2026 | Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arbitrary files with session information via the sid parameter. | |
| Modificada | Media (4.3) | 2.1% | — | Amax Information Technologies Magic Winmail Server | 19/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) retid parameter in badlogin.php, (2) Content-Type headers in HTML mails, and (3) HTML mail attachments. | |
| Modificada | Media (5) | 1.4% | — | Icewarp WEB MailMerak Mail Server | 4/10/2005 | 16/6/2026 | MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to bwlist_inc.html, which reveals the path in an error message. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Icewarp WEB MailMerak Mail Server | 4/10/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or… | |
| Modificada | Media (5) | 6.1% | 💥 Exploit | Icewarp WEB MailMerak Mail Server | 4/10/2005 | 16/6/2026 | Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary files or directories via a relative path to the id parameter to logout.html or (2) include arbitrary PHP files or other files via the… | |
| Modificada | Media (5) | 0.92% | — | Double Precision Incorporated Courier Mail Server | 6/7/2005 | 16/6/2026 | spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption. |