Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2533▼ 405 respecto a la semana anterior
Críticas / altas1319▲ 38 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)1.0%—Sagredo QmailAI16/4/202617/6/2026
sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.
AplazadaMedia (6.5)0.32%—Tencent Technology Qqmail IOSAI27/1/202517/6/2026
An issue in Tencent Technology (Shenzhen) Company Limited QQMail iOS 6.6.4 allows attackers to access sensitive user information via supplying a crafted link.
ModificadaAlta (8.8)0.38%—Qnap Qmailagent20/11/202117/6/2026
We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later
ModificadaMedia (6.1)0.71%—Qnap Qmailagent13/11/202117/6/2026
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later
ModificadaMedia (5.9)0.95%—Fehcom S/qmail17/8/202117/6/2026
In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker.
ModificadaMedia (5.5)0.43%—NetqmailDebian LinuxCanonical Ubuntu Linux26/5/202017/6/2026
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its…
ModificadaAlta (7.5)1.8%—NetqmailDebian LinuxCanonical Ubuntu Linux26/5/202017/6/2026
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
ModificadaCrítica (9.8)1.7%—Marmaro Masqmail19/11/201916/6/2026
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
ModificadaMedia (6.8)4.6%—Frederik Vermeulen Netqmail16/3/201116/6/2026
The STARTTLS implementation in qmail-smtpd.c in qmail-smtpd in the netqmail-1.06-tls patch for netqmail 1.06 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related…
ModificadaMedia (5)2.6%—Gazatem Technologies Qmail Mailing List Manager16/12/200816/6/2026
Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for qmail.mdb.
ModificadaAlta (7.5)4.6%—Inter7 Qmailadmin10/3/200616/6/2026
Buffer overflow in qmailadmin.c in QmailAdmin before 1.2.10 allows remote attackers to execute arbitrary code via a long PATH_INFO environment variable.
ModificadaBaja (2.1)0.36%—Masqmail21/9/200516/6/2026
masqmail before 0.2.18 allows local users to overwrite arbitrary files via a symlink attack on a log file.
ModificadaAlta (7.5)2.4%—Masqmail21/9/200516/6/2026
masqmail before 0.2.18 allows remote attackers to execute arbitrary commands via crafted e-mail addresses that are not properly sanitized when creating a failed delivery message.
ModificadaCrítica (9.8)11%—Qmail Project QmailCanonical Ubuntu LinuxDebian Linux11/5/200516/6/2026
Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.
ModificadaMedia (5)6.5%—DAN Bernstein Qmail11/5/200516/6/2026
Integer signedness error in the qmail_put and substdio_put functions in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of SMTP RCPT TO commands.
ModificadaMedia (5)6.6%—DAN Bernstein Qmail11/5/200516/6/2026
commands.c in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SMTP command without a space character, which causes an array to be referenced with a negative index.
ModificadaMedia (4.6)0.86%—Inter7 Qmailadmin11/4/200316/6/2026
Buffer overflow in qmailadmin allows local users to gain privileges via a long QMAILADMIN_TEMPLATEDIR environment variable.
ModificadaAlta (7.2)0.40%—Masqmail29/11/200216/6/2026
Multiple buffer overflows in conf.c for Masqmail 0.1.x before 0.1.17, and 0.2.x before 0.2.15, allow local users to gain privileges via certain entries in the configuration file (-C option).
ModificadaAlta (7.2)0.34%—Masqmail26/7/200116/6/2026
Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.
ModificadaAlta (10)2.3%—DAN Bernstein Qmail1/7/199716/6/2026
Denial of service in Qmail through long SMTP commands.
ModificadaBaja (2.1)1.3%—Qmail Project Qmail1/6/199716/6/2026
Denial of service in Qmail by specifying a large number of recipients with the RCPT command.