Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2493▼ 464 respecto a la semana anterior
Críticas / altas1281▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 1.0% | — | Sagredo QmailAI | 16/4/2026 | 17/6/2026 | sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c. | |
| Aplazada | Media (6.5) | 0.32% | — | Tencent Technology Qqmail IOSAI | 27/1/2025 | 17/6/2026 | An issue in Tencent Technology (Shenzhen) Company Limited QQMail iOS 6.6.4 allows attackers to access sensitive user information via supplying a crafted link. | |
| Modificada | Alta (8.8) | 0.38% | — | Qnap Qmailagent | 20/11/2021 | 17/6/2026 | We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later | |
| Modificada | Media (6.1) | 0.71% | — | Qnap Qmailagent | 13/11/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later | |
| Modificada | Media (5.9) | 0.95% | — | Fehcom S/qmail | 17/8/2021 | 17/6/2026 | In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker. | |
| Modificada | Media (5.5) | 0.43% | — | NetqmailDebian LinuxCanonical Ubuntu Linux | 26/5/2020 | 17/6/2026 | qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its… | |
| Modificada | Alta (7.5) | 1.8% | — | NetqmailDebian LinuxCanonical Ubuntu Linux | 26/5/2020 | 17/6/2026 | qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Marmaro Masqmail | 19/11/2019 | 16/6/2026 | masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping. | |
| Modificada | Media (6.8) | 4.6% | — | Frederik Vermeulen Netqmail | 16/3/2011 | 16/6/2026 | The STARTTLS implementation in qmail-smtpd.c in qmail-smtpd in the netqmail-1.06-tls patch for netqmail 1.06 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related… | |
| Modificada | Media (5) | 2.6% | — | Gazatem Technologies Qmail Mailing List Manager | 16/12/2008 | 16/6/2026 | Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for qmail.mdb. | |
| Modificada | Alta (7.5) | 4.6% | — | Inter7 Qmailadmin | 10/3/2006 | 16/6/2026 | Buffer overflow in qmailadmin.c in QmailAdmin before 1.2.10 allows remote attackers to execute arbitrary code via a long PATH_INFO environment variable. | |
| Modificada | Baja (2.1) | 0.36% | — | Masqmail | 21/9/2005 | 16/6/2026 | masqmail before 0.2.18 allows local users to overwrite arbitrary files via a symlink attack on a log file. | |
| Modificada | Alta (7.5) | 2.4% | — | Masqmail | 21/9/2005 | 16/6/2026 | masqmail before 0.2.18 allows remote attackers to execute arbitrary commands via crafted e-mail addresses that are not properly sanitized when creating a failed delivery message. | |
| Modificada | Crítica (9.8) | 11% | — | Qmail Project QmailCanonical Ubuntu LinuxDebian Linux | 11/5/2005 | 16/6/2026 | Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request. | |
| Modificada | Media (5) | 6.5% | — | DAN Bernstein Qmail | 11/5/2005 | 16/6/2026 | Integer signedness error in the qmail_put and substdio_put functions in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of SMTP RCPT TO commands. | |
| Modificada | Media (5) | 6.6% | — | DAN Bernstein Qmail | 11/5/2005 | 16/6/2026 | commands.c in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SMTP command without a space character, which causes an array to be referenced with a negative index. | |
| Modificada | Media (4.6) | 0.86% | — | Inter7 Qmailadmin | 11/4/2003 | 16/6/2026 | Buffer overflow in qmailadmin allows local users to gain privileges via a long QMAILADMIN_TEMPLATEDIR environment variable. | |
| Modificada | Alta (7.2) | 0.40% | — | Masqmail | 29/11/2002 | 16/6/2026 | Multiple buffer overflows in conf.c for Masqmail 0.1.x before 0.1.17, and 0.2.x before 0.2.15, allow local users to gain privileges via certain entries in the configuration file (-C option). | |
| Modificada | Alta (7.2) | 0.34% | — | Masqmail | 26/7/2001 | 16/6/2026 | Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases. | |
| Modificada | Alta (10) | 2.3% | — | DAN Bernstein Qmail | 1/7/1997 | 16/6/2026 | Denial of service in Qmail through long SMTP commands. | |
| Modificada | Baja (2.1) | 1.3% | — | Qmail Project Qmail | 1/6/1997 | 16/6/2026 | Denial of service in Qmail by specifying a large number of recipients with the RCPT command. |