Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
177 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.77% | — | Anti-spam Smtp Proxy Project Anti-spam Smtp Proxy | 8/11/2017 | 17/6/2026 | The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access to the assp user account to install a Trojan horse /usr/share/assp/assp.pl script. | |
| Modificada | Crítica (9.8) | 4.0% | — | Openbsd OpensmtpdFedoraproject Fedora | 16/10/2017 | 17/6/2026 | Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Media (6.1) | 0.78% | — | Wp-ecommerce Easy WP Smtp | 24/4/2017 | 17/6/2026 | XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body. | |
| Modificada | Media (5) | 2.5% | — | Openbsd Opensmtpd | 27/5/2014 | 16/6/2026 | OpenSMTPD before 5.3.2 does not properly handle SSL sessions, which allows remote attackers to cause a denial of service (connection blocking) by keeping a connection open. | |
| Modificada | Baja (2.1) | 1.1% | 💥 Exploit | Anibal Monsalve Salaz Ssmtp | 20/8/2010 | 16/6/2026 | The standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denial of service (application exit) via an e-mail message containing a long line that begins with a . (dot) character. NOTE: CVE disputes this issue because it is solely a usability problem for senders of messages… | |
| Modificada | Media (6.8) | 1.2% | — | Stafford.uklinux Libesmtp | 31/3/2010 | 16/6/2026 | The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName. | |
| Modificada | Media (6.8) | 0.86% | — | Stafford.uklinux Libesmtp | 31/3/2010 | 16/6/2026 | libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related… | |
| Modificada | Media (6.4) | 1.1% | — | Martin Lambers Msmtp | 16/11/2009 | 16/6/2026 | Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued… | |
| Modificada | Baja (3.5) | 1.00% | — | Mailmarshal E10000 ApplianceMailmarshal Smtp | 2/10/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the delegated spam management feature in the Spam Quarantine Management (SQM) component in MailMarshal SMTP 6.0.3.8 through 6.3.0.0 allow user-assisted remote authenticated users to inject arbitrary web script or HTML via (1) the list of blocked senders or (2) the… | |
| Modificada | Baja (2.6) | 2.0% | — | Ssmtp | 11/9/2008 | 16/6/2026 | The from_format function in ssmtp.c in ssmtp 2.61 and 2.62, in certain configurations, uses uninitialized memory for the From: field of an e-mail message, which might allow remote attackers to obtain sensitive information (memory contents) in opportunistic circumstances by reading a message. | |
| Modificada | Media (5) | 13% | — | Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+5 | 13/5/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438. | |
| Modificada | Media (5) | 13% | — | Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+5 | 13/5/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large… | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Citadel Smtp | 23/1/2008 | 16/6/2026 | Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function. NOTE: some of these details were obtained from third party information. | |
| Modificada | Alta (7.8) | 1.6% | — | Qksoft QK Smtp Server 3 | 28/12/2007 | 16/6/2026 | QK SMTP Server 3 allows remote attackers to cause a denial of service (daemon crash) via a long (1) HELO, (2) MAIL FROM, or (3) RCPT TO command; or (4) a long string in the message sent after the DATA command; possibly a related issue to CVE-2006-5551. | |
| Modificada | Alta (7.5) | 1.4% | — | Anti-spam Smtp Proxy Server | 10/8/2007 | 16/6/2026 | Unspecified vulnerability in assp.pl in Anti-Spam SMTP Proxy Server (ASSP) 1.3.3 has unknown impact and attack vectors. | |
| Modificada | Alta (7.6) | 1.9% | — | Mailmarshal Smtp | 17/7/2007 | 16/6/2026 | The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length… | |
| Modificada | Alta (10) | 3.9% | — | Mailmarshal Smtp | 10/11/2006 | 16/6/2026 | Directory traversal vulnerability in Marshal MailMarshal SMTP 5.x, 6.x, and 2006, and MailMarshal for Exchange 5.x, allows remote attackers to write arbitrary files via ".." sequences in filenames in an ARJ compressed archive. | |
| Modificada | Alta (7.5) | 5.2% | 💥 Exploit | Qksoft QK Smtp | 26/10/2006 | 16/6/2026 | Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a long argument to the RCPT TO command. | |
| Modificada | Media (4) | 1.1% | — | John Hanna Anti-spam Smtp Proxy Server | 21/8/2006 | 16/6/2026 | Absolute path traversal vulnerability in the get functionality in Anti-Spam SMTP Proxy (ASSP) allows remote authenticated users to read arbitrary files via (1) C:\ (Windows drive letter), (2) UNC, and possibly other types of paths in the file parameter. | |
| Modificada | Media (5) | 1.9% | — | Clearswift Mailsweeper FOR ExchangeClearswift Mailsweeper FOR Smtp | 24/6/2006 | 16/6/2026 | Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed… | |
| Modificada | Alta (7.5) | 1.7% | — | Clearswift Mailsweeper FOR ExchangeClearswift Mailsweeper FOR Smtp | 24/6/2006 | 16/6/2026 | Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to bypass the "text analysis", possibly bypassing SPAM and other filters, by sending an e-mail specifying a non-existent or unrecognized character set. | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | BL4 Smtp Server | 29/4/2006 | 16/6/2026 | Buffer overflow in BL4 SMTP Server 0.1.4 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the (1) EHLO, (2) MAIL FROM, and (3) RCPT TO commands. | |
| Modificada | Alta (10) | 6.1% | — | Mcafee Webshield Smtp | 4/4/2006 | 16/6/2026 | Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce message is constructed. | |
| Modificada | Alta (7.5) | 4.6% | — | E-post Corporation Mail ServerE-post Corporation Smtp ServerE-post Corporation Spa-pro Mail Atsolomon | 27/1/2006 | 16/6/2026 | Multiple buffer overflows in E-Post Mail Server 4.10 and SPA-PRO Mail @Solomon 4.00 allow remote attackers to execute arbitrary code via a long username to the (1) AUTH PLAIN or (2) AUTH LOGIN SMTP commands, which is not properly handled by (a) EPSTRS.EXE or (b) SPA-RS.EXE; (3) a long username in the APOP POP3… |