Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Sendcard | 2/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the form parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Sendcard | 2/5/2007 | 16/6/2026 | Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrary files via a full pathname in the form parameter. | |
| Modificada | Alta (7.8) | 2.3% | — | Sendmail | 25/4/2007 | 16/6/2026 | Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of… | |
| Modificada | Alta (7.5) | 0.82% | — | Sendmail | 27/3/2007 | 16/6/2026 | The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired. | |
| Modificada | Media (4.3) | 2.0% | — | Sendmail | 27/3/2007 | 16/6/2026 | The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages. | |
| Modificada | Media (6.8) | 8.0% | 💥 Exploit | Interspire Sendstudio | 22/2/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOTDIR parameter to (1) createemails.inc.php and (2) send_emails.inc.php in /admin/includes/. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Textsend | 21/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter. | |
| Modificada | Media (6.8) | 1.1% | — | Carsen Klock Textsend | 21/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Carsen Klock TextSend 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) error or (2) success parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 4.5% | — | Sendmail | 29/8/2006 | 16/6/2026 | Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is… | |
| Modificada | Media (5) | 5.3% | — | Sendmail | 7/6/2006 | 16/6/2026 | Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmail from delivering queued messages and might lead to disk… | |
| Modificada | Alta (7.6) | 29% | 💥 Exploit | Sendmail | 22/3/2006 | 16/6/2026 | Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations. | |
| Modificada | Alta (7.5) | 1.2% | — | Sendcard | 6/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in sendcard.php in sendcard before 3.3.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters. | |
| Modificada | Media (5) | 1.6% | — | Theworldsend.net Php-ping | 31/1/2006 | 16/6/2026 | PHP-Ping 1.3 does not properly validate ping counts, which allows remote attackers to cause a denial of service (ping flood) via a negative count parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Sendcard | 27/7/2005 | 16/6/2026 | SQL injection vulnerability in sendcard.php in Sendcard 3.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 1.7% | — | Sendmail | 29/6/2005 | 16/6/2026 | The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading. | |
| Modificada | Baja (2.1) | 0.62% | 💥 Exploit | SendlinkAI | 23/2/2005 | 16/6/2026 | SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges. | |
| Modificada | Media (5) | 3.6% | — | Redhat SendmailSendmailSGI IrixCompaq Tru64+2 | 20/10/2003 | 16/6/2026 | The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data. | |
| Modificada | Alta (10) | 66% | — | Sendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+14 | 6/10/2003 | 16/6/2026 | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Sendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+10 | 6/10/2003 | 16/6/2026 | A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences. | |
| Modificada | Alta (7.2) | 0.40% | — | SendmailDebian Linux | 15/5/2003 | 16/6/2026 | The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl. | |
| Modificada | Alta (10) | 39% | 💥 Exploit | SendmailSendmail SwitchCompaq Tru64Hp-ux+5 | 2/4/2003 | 16/6/2026 | The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial… | |
| Modificada | Media (5) | 1.4% | — | Acuma Acusend | 31/3/2003 | 16/6/2026 | Acuma Acusend 4, and possibly earlier versions, allows remote authenticated users to read the reports of other users by inferring the full URL, whose name is easily predictable. | |
| Modificada | Alta (10) | 73% | 💥 Exploit | SendmailHP Alphaserver SCGentoo LinuxHp-ux+5 | 7/3/2003 | 16/6/2026 | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c. | |
| Modificada | Alta (7.5) | 2.0% | — | Sendmail | 31/12/2002 | 16/6/2026 | Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS hostname. | |
| Modificada | Baja (2.1) | 0.93% | 💥 Exploit | Sendmail | 31/12/2002 | 16/6/2026 | Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map, (3) statistics, and (4) pid files. |