Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2493▼ 464 respecto a la semana anterior
Críticas / altas1281▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | Claws-mailSylpheed Project SylpheedFedoraproject Fedora | 30/7/2021 | 17/6/2026 | textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click. | |
| Modificada | Alta (8.8) | 1.2% | — | Sylpheed Project Sylpheed | 14/12/2017 | 17/6/2026 | libsylph/utils.c in Sylpheed through 3.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. | |
| Modificada | Media (6.8) | 3.2% | — | SylpheedSylpheed-claws | 27/8/2007 | 16/6/2026 | Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies. | |
| Modificada | Media (5) | 2.0% | — | Sylpheed | 6/3/2007 | 16/6/2026 | Sylpheed 2.2.7 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Sylpheed from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection. | |
| Modificada | Baja (2.6) | 1.4% | — | SylpheedSylpheed-claws | 9/6/2006 | 16/6/2026 | Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote attackers to bypass the URI check functionality and makes it easier to conduct phishing attacks via a URI that begins with a space character. | |
| Modificada | Media (5.1) | 3.8% | — | Sylpheed | 20/11/2005 | 16/6/2026 | Stack-based buffer overflow in the ldif_get_line function in ldif.c of Sylpheed before 2.1.6 allows user-assisted attackers to execute arbitrary code by having local users import LDIF files with long lines. | |
| Modificada | Media (5.1) | 1.8% | — | Sylpheed | 2/5/2005 | 16/6/2026 | Buffer overflow in Sylpheed before 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attachments with MIME-encoded file names. | |
| Modificada | Media (5.1) | 3.2% | — | SylpheedSylpheed-clawsAltlinux ALT LinuxGentoo Linux+3 | 7/3/2005 | 16/6/2026 | Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message. | |
| Modificada | Media (5) | 1.4% | — | SylpheedSylpheed-claws | 17/11/2003 | 16/6/2026 | Format string vulnerability in send_message.c for Sylpheed-claws 0.9.4 through 0.9.6 allows remote SMTP servers to cause a denial of service (crash) in sylpheed via format strings in an error message. | |
| Modificada | Media (5) | 3.4% | — | Microsoft Outlook ExpressMozillaMuttQualcomm Eudora+4 | 16/6/2003 | 16/6/2026 | The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors. |