Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Clearswift Mailsweeper | 28/9/2004 | 16/6/2026 | Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy. | |
| Modificada | Alta (7.5) | 1.3% | — | Clearswift Mailsweeper | 28/9/2004 | 16/6/2026 | Clearswift MAILsweeper before 4.3.15 does not properly detect filenames in BinHex (HQX) encoded files, which allows remote attackers to bypass intended policy. | |
| Modificada | Media (6.4) | 4.1% | — | Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+9 | 18/8/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path"). | |
| Modificada | Alta (10) | 10% | — | Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+9 | 18/8/2004 | 16/6/2026 | Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the… | |
| Modificada | Media (5) | 2.0% | — | Clearswift Mimesweeper FOR WEB | 11/8/2004 | 16/6/2026 | Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via "..\\", "..\", and similar dot dot sequences in the URL. | |
| Modificada | Media (5) | 1.4% | — | Clearswift Limited Mailsweeper | 31/12/2003 | 16/6/2026 | Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove. | |
| Modificada | Alta (7.5) | 1.7% | — | Clearswift Mailsweeper | 31/12/2003 | 16/6/2026 | MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants. | |
| Modificada | Media (5) | 1.3% | — | Clearswift Mailsweeper | 31/12/2003 | 16/6/2026 | Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space." | |
| Modificada | Alta (7.8) | 1.6% | — | Clearswift Mailsweeper FOR Smtp | 31/12/2003 | 16/6/2026 | MAILsweeper for SMTP 4.3.6 and 4.3.7 allows remote attackers to cause a denial of service (CPU consumption) via a PowerPoint attachment that either (1) is corrupt or (2) contains "embedded objects." | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Clearswift Mailsweeper | 18/3/2003 | 16/6/2026 | Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients. | |
| Modificada | Alta (7.5) | 1.3% | — | Clearswift Limited Mailsweeper | 31/12/2001 | 16/6/2026 | The File Blocker feature in Clearswift MAILsweeper for SMTP 4.2 allows remote attackers to bypass e-mail attachment filtering policies via a modified name in a Content-Type header. | |
| Modificada | Media (5) | 1.3% | — | Clearswift Mailsweeper FOR Smtp | 19/12/2000 | 23/9/2026 | MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service. |