Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.17% | — | Mailscanner | 12/11/2019 | 16/6/2026 | The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing. | |
| Modificada | Media (4.7) | 0.34% | — | Mailscanner | 12/11/2019 | 16/6/2026 | mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-5313. | |
| Modificada | Media (5.5) | 0.37% | — | Mailscanner | 28/10/2019 | 16/6/2026 | mailscanner can allow local users to prevent virus signatures from being updated | |
| Modificada | Media (6.9) | 0.30% | — | Mailscanner | 3/12/2008 | 16/6/2026 | mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) avast-autoupdate, and (4) f-prot-6-autoupdate scripts in /etc/MailScanner/autoupdate/; the (5)… | |
| Modificada | Media (6.9) | 0.30% | — | Mailscanner | 3/12/2008 | 16/6/2026 | mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) panda-autoupdate.new, (4) trend-autoupdate.new, and (5) rav-autoupdate.new scripts in… | |
| Modificada | Media (6.9) | 0.33% | — | Debian Mailscanner | 18/11/2008 | 16/6/2026 | trend-autoupdate.new in mailscanner 4.55.10 and other versions before 4.74.16-1 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/opr.ini.##### or (2) /tmp/lpt*.zip temporary file. | |
| Modificada | Media (5) | 2.8% | — | Microworld Technologies Mailscan | 20/8/2008 | 16/6/2026 | Directory traversal vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Alta (7.5) | 1.7% | — | Microworld Technologies Mailscan | 20/8/2008 | 16/6/2026 | Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to bypass authentication and obtain administrative access via a direct request with (1) an IsAdmin=true cookie value or (2) no cookie. | |
| Modificada | Media (5) | 1.6% | — | Microworld Technologies Mailscan | 20/8/2008 | 16/6/2026 | Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to determine the installation path, IP addresses, and error messages via direct requests to files under LOG/. | |
| Modificada | Media (4.3) | 1.3% | — | Microworld Technologies Mailscan | 20/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to inject arbitrary web script or HTML via the URI. | |
| Modificada | Alta (7.5) | 1.3% | — | Mailscanner | 2/11/2005 | 16/6/2026 | SQL injection vulnerability in in the authenticate function in MailWatch for MailScanner 1.0.2 allows remote attackers to execute arbitrary SQL commands. | |
| Modificada | Media (5) | 1.7% | — | Mailwatch FOR MailscannerAI | 2/11/2005 | 16/6/2026 | Directory traversal vulnerability in the ruleset view for MailWatch for MailScanner 1.0.2 allows remote attackers to access arbitrary files. | |
| Modificada | Alta (7.5) | 1.4% | — | Mailscanner | 24/5/2005 | 16/6/2026 | Unknown vulnerability in MailScanner 4.41.3 and earlier, related to "incomplete reporting of viruses in zip files," allows remote attackers to bypass virus detection. | |
| Modificada | Media (6.4) | 1.1% | — | Mailscanner | 31/12/2002 | 16/6/2026 | MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate character encodings that cannot be processed by MailScanner. |