Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.17% | — | Mailscanner | 12/11/2019 | 16/6/2026 | The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing. | |
| Modificada | Media (4.7) | 0.34% | — | Mailscanner | 12/11/2019 | 16/6/2026 | mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-5313. | |
| Modificada | Media (5.5) | 0.37% | — | Mailscanner | 28/10/2019 | 16/6/2026 | mailscanner can allow local users to prevent virus signatures from being updated | |
| Modificada | Media (6.9) | 0.30% | — | Mailscanner | 3/12/2008 | 16/6/2026 | mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) avast-autoupdate, and (4) f-prot-6-autoupdate scripts in /etc/MailScanner/autoupdate/; the (5)… | |
| Modificada | Media (6.9) | 0.30% | — | Mailscanner | 3/12/2008 | 16/6/2026 | mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) panda-autoupdate.new, (4) trend-autoupdate.new, and (5) rav-autoupdate.new scripts in… | |
| Modificada | Media (6.9) | 0.33% | — | Debian Mailscanner | 18/11/2008 | 16/6/2026 | trend-autoupdate.new in mailscanner 4.55.10 and other versions before 4.74.16-1 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/opr.ini.##### or (2) /tmp/lpt*.zip temporary file. | |
| Modificada | Alta (7.5) | 1.3% | — | Mailscanner | 2/11/2005 | 16/6/2026 | SQL injection vulnerability in in the authenticate function in MailWatch for MailScanner 1.0.2 allows remote attackers to execute arbitrary SQL commands. | |
| Modificada | Media (5) | 1.7% | — | Mailwatch FOR MailscannerAI | 2/11/2005 | 16/6/2026 | Directory traversal vulnerability in the ruleset view for MailWatch for MailScanner 1.0.2 allows remote attackers to access arbitrary files. | |
| Modificada | Alta (7.5) | 1.4% | — | Mailscanner | 24/5/2005 | 16/6/2026 | Unknown vulnerability in MailScanner 4.41.3 and earlier, related to "incomplete reporting of viruses in zip files," allows remote attackers to bypass virus detection. | |
| Modificada | Media (6.4) | 1.1% | — | Mailscanner | 31/12/2002 | 16/6/2026 | MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate character encodings that cannot be processed by MailScanner. |