在 Progressive Robot hMailServer 6.0.0 至 6.3.5 版本(仅限 Windows)中,COM 对象存在授权缺失漏洞,允许任何本地交互式用户(无需 hMailServer 凭据)以服务账户身份读写任意文件,并伪造任意发件人发送电子邮件。 该服务在注册其 COM 类时未设置 DCOM 访问权限或启动权限,并调用 而未指定安全描述符。因此,任何通过控制台或远程桌面(RDP)登录系统的用户,均可激活运行中服务内的 COM 类。通过这种方式创建的 对象、其 和 对象,以及 对象,均携带从
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progressive Robot Ltd | hMailServer | 6.0.0 ~ 6.3.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103647 | 8.0 HIGH | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hM |
| CVE-2026-103010 | 7.8 HIGH | Heap-based Buffer Overflow in hMailServer |
| CVE-2026-107573 | 7.8 HIGH | Incorrect Default Permissions in hMailServer |
| CVE-2026-104658 | 7.8 HIGH | Reliance on Untrusted Inputs in a Security Decision in hMailServer |
| CVE-2026-103649 | 7.5 HIGH | Synchronous Access of Remote Resource without Timeout in hMailServer |
| CVE-2026-107577 | 7.5 HIGH | Loop with Unreachable Exit Condition ('Infinite Loop') in hMailServer |
| CVE-2026-107574 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107579 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107576 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-104659 | 7.5 HIGH | Origin Validation Error in hMailServer |
| CVE-2026-107584 | 7.4 HIGH | Not Failing Securely ('Failing Open') in hMailServer |
| CVE-2026-104704 | 7.4 HIGH | Cleartext Transmission of Sensitive Information in hMailServer |
| CVE-2026-107578 | 6.7 MEDIUM | Improper Link Resolution Before File Access ('Link Following') in hMailServer |
| CVE-2026-103011 | 6.5 MEDIUM | Heap-based Buffer Overflow in hMailServer |
| CVE-2026-107583 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107572 | 6.5 MEDIUM | Inefficient Regular Expression Complexity in hMailServer |
| CVE-2026-107581 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107582 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107580 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107587 | 5.9 MEDIUM | Improper Certificate Validation in hMailServer |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet