Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

177 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.0%—Hitachi Groupmax Mail Smtp17/12/200516/6/2026
Hitachi Groupmax Mail SMTP 06-50 through 06-52-/A and 07-00 through 07-20 allows remote attackers to cause a denial of service (service stop) via an e-mail message with an "invalid format."
ModificadaAlta (7.5)2.6%💥 ExploitSoftstack Free Smtp Server8/9/200516/6/2026
Free SMTP Server 2.2 allows remote attackers to use the server as an open mail relay (spam proxy).
ModificadaAlta (7.5)9.9%💥 ExploitNbsmtp1/8/200516/6/2026
Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via format string specifiers that are not properly handled in a syslog call.
ModificadaAlta (7.5)3.1%—Goodtech Systems Goodtech Smtp Server27/7/200516/6/2026
Multiple stack-based buffer overflows in GoodTech SMTP server 5.16 allow remote attackers to execute arbitrary code via (1) a RCPT TO command with a long DNS name, or (2) a large number of RCPT TO commands with a long e-mail name arugment in the last command.
ModificadaMedia (5)2.5%💥 ExploitGoodtech Systems Goodtech Smtp Server5/7/200516/6/2026
GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.
ModificadaAlta (7.5)1.9%—Debian Bsmtpd25/2/200516/6/2026
bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.
ModificadaAlta (7.5)2.5%💥 ExploitAmir Malik Qwik Smtpd10/1/200516/6/2026
Buffer overflow in qwik-smtpd allows remote attackers to use the server as an SMTP spam relay via a long HELO command, which overwrites the adjacent localIP data buffer.
ModificadaMedia (4.3)1.1%—Clearswift Mailsweeper Business Suite IClearswift Mailsweeper Business Suite IIClearswift Mailsweeper FOR SmtpClearswift Mimesweeper FOR WEB31/12/200416/6/2026
Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".
ModificadaAlta (7.5)2.7%—Smtp.proxy31/12/200416/6/2026
Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) client hostname or (2) message-id, which are injected into a syslog message.
ModificadaAlta (7.5)6.5%💥 ExploitQwikmail Smtp31/12/200416/6/2026
Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.
ModificadaBaja (2.1)0.30%—Ssmtp7/7/200416/6/2026
The log_event function in ssmtp 2.50.6 and earlier allows local users to overwrite arbitrary files via a symlink attack on the ssmtp.log temporary log file.
ModificadaMedia (5)3.5%—Ssmtp1/6/200416/6/2026
Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.
ModificadaAlta (7.8)1.6%—Clearswift Mailsweeper FOR Smtp31/12/200316/6/2026
MAILsweeper for SMTP 4.3.6 and 4.3.7 allows remote attackers to cause a denial of service (CPU consumption) via a PowerPoint attachment that either (1) is corrupt or (2) contains "embedded objects."
ModificadaMedia (5)1.8%—Incognito Software INC Ismtp Gateway31/12/200216/6/2026
iSMTP 5.0.1 allows remote attackers to cause a denial of service via a long "MAIL FROM" command, possibly triggering a buffer overflow.
ModificadaAlta (7.5)2.0%—Libesmtp4/10/200216/6/2026
Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses.
ModificadaAlta (7.5)6.7%—GFI MailsecurityNetwork Associates Webshield SmtpRoaring Penguin CanitRoaring Penguin Mimedefang+124/9/200216/6/2026
SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly")…
ModificadaAlta (7.5)2.8%—Network Associates Webshield Smtp31/12/200116/6/2026
NAI WebShield SMTP 4.5 and possibly 4.5 MR1a does not filter improperly MIME encoded email attachments, which could allow remote attackers to bypass filtering and possibly execute arbitrary code in email clients that process the invalid attachments.
ModificadaAlta (7.5)5.7%—Mcafee Webshield SmtpNetwork Associates Gauntlet FirewallPGP E-ppliance 300SGI Irix+14/9/200116/6/2026
Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.
ModificadaAlta (7.5)1.5%—Network Associates Webshield Smtp9/1/200116/6/2026
McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment.
ModificadaMedia (5)2.5%💥 ExploitNetwork Associates Webshield Smtp9/1/200116/6/2026
McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.
ModificadaMedia (5)1.3%—Clearswift Mailsweeper FOR Smtp19/12/200023/9/2026
MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service.
ModificadaAlta (10)10%💥 ExploitJack DE Winter Winsmtp14/11/200016/6/2026
Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.
ModificadaMedia (5)1.7%—Network Associates Webshield Smtp20/10/200016/6/2026
WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.
ModificadaAlta (7.5)1.9%—Tenfour TFS Gateway Smtp2/9/199916/6/2026
A buffer overflow in TenFour TFS Gateway SMTP mail server 3.2 allows an attacker to crash the mail server and possibly execute arbitrary code by offering more than 128 bytes in a MAIL FROM string.
ModificadaMedia (5)1.4%—Microsoft Smtp ServiceAI1/3/199916/6/2026
When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.
Orbitaley — Vulnerabilidades