Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.4% | — | Courier-mta Courier Mail Server | 3/8/2021 | 17/6/2026 | An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can pipeline commands after the POP3 STLS command, injecting plaintext commands into an encrypted user session. | |
| Modificada | Media (5.1) | 1.8% | — | Courier-mta Courtier-authlib | 22/12/2008 | 16/6/2026 | SQL injection vulnerability in authpgsqllib.c in Courier-Authlib before 0.62.0, when a non-Latin locale Postgres database is used, allows remote attackers to execute arbitrary SQL commands via query parameters containing apostrophes. | |
| Modificada | Media (5.1) | 1.5% | — | Courier-mta Courtier-authlib | 7/7/2008 | 16/6/2026 | SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors. | |
| Modificada | Alta (7.8) | 2.4% | — | Double Precision Incorporated Courier MTA | 30/5/2006 | 16/6/2026 | libs/comverp.c in Courier MTA before 0.53.2 allows attackers to cause a denial of service (CPU consumption) via unknown vectors involving usernames that contain the "=" (equals) character, which is not properly handled during encoding. | |
| Modificada | Alta (7.5) | 3.3% | — | Double Precision Incorporated Courier MTADouble Precision Incorporated SqwebmailInter7 Courier-imapGentoo Linux | 15/4/2004 | 16/6/2026 | Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range." | |
| Modificada | Alta (7.5) | 1.2% | — | Double Precision Incorporated Courier MTAInter7 Courier-imap | 19/2/2003 | 16/6/2026 | SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name. | |
| Modificada | Media (4.6) | 0.34% | — | Double Precision Incorporated Courier MTA | 29/11/2002 | 16/6/2026 | Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files. | |
| Modificada | Media (5) | 1.7% | — | Double Precision Incorporated Courier MTA | 4/10/2002 | 16/6/2026 | Double Precision Courier e-mail MTA allows remote attackers to cause a denial of service (CPU consumption) via a message with an extremely large or negative value for the year, which causes a tight loop. |