Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.5%—Isync Project IsyncFedoraproject FedoraRedhat Enterprise LinuxDebian Linux18/2/202217/6/2026
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.
ModificadaAlta (7.8)1.0%—Isync Project IsyncFedoraproject FedoraDebian Linux16/2/202217/6/2026
A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the…
ModificadaCrítica (9.8)3.8%—Isync Project IsyncDebian LinuxFedoraproject Fedora22/11/202117/6/2026
A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be exploited for remote code execution.
ModificadaMedia (4.3)1.3%—Isync Project Isync23/5/201416/6/2026
Isync 0.4 before 1.0.6, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
ModificadaAlta (9.3)3.9%—RIM Blackberry Desktop SoftwareIBM Lotus Notes Intellisync4/11/200916/6/2026
Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page. NOTE: some of these details are obtained from third party…
ModificadaMedia (4.3)2.7%—Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express11/5/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to…
ModificadaMedia (6.4)1.5%—Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express11/5/200716/6/2026
Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to obtain user names and other sensitive information via a direct request to (1) usrmgr/userList.asp or (2) usrmgr/userStatusList.asp.
ModificadaAlta (7.5)1.8%—Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express11/5/200716/6/2026
usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify user account details and cause a denial of service (account deactivation) via the userid parameter in…
ModificadaAlta (7.2)1.3%—Isync Mrouter22/1/200516/6/2026
Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.